Compare commits

..
Author SHA1 Message Date
fargo 9d3e22b1c1 fix(fleet): activate the lease broker at install/start, place units through symlinks safely, refuse doomed launches (#1292)
ci/woodpecker/pr/ci Pipeline failed
Wall 6: no documented path ever enabled or started the shipped
mosaic-lease-broker.service — every gated runtime died ~4s in at lease
registration while fleet start reported rc0, and a broker not in the
reconciler plan could not be reported as drifted.

Activation lands in the control plane, not the launcher:

- fleet install places ALL FOUR units through placeUnitFile — a placement
  helper that unlinks any by-path-enable symlink at the destination
  BEFORE copying (Node copyFile follows the link and overwrites the SEED
  template; measured on a throwaway systemd user instance 2026-08-17,
  with both cp and fs.copyFile), removes a stale wants-symlink pointing
  outside the active dir (readlink — readFile returns the target's
  content, not the link path), then copies and daemon-reloads. The same
  measurement showed systemctl enable <name> does NOT rewrite an existing
  by-path wants-symlink — reconciliation must be explicit. Idempotent:
  second install on by-path residue converges to the identical state.
  Until now the copy block named three units and omitted the broker, and
  the residue set / copy set were disjoint only by accident (fomo-lin
  survived copy-through because its one symlink was the one unit not
  copied); adding the broker made them intersect on first run. See the
  SET-INDEPENDENCE note on the helper before adding a fifth unit.
- enableFleetUnits enables the broker first, alongside the holder.
- fleet start / reconciler start the broker BEFORE any holder/agent
  lifecycle effect, then RE-CHECK the socket (not unit state) and exit
  nonzero with a named code if it did not appear. Re-probed on every
  invocation — a RemainAfterExit=yes dead-looking-active unit can never
  make retry look like repair (the sticky-retry check).
- The reconciler plan carries broker {unitInstalled, socketPresent} as a
  first-class member; the socket is the signal (enabled-but-dead units
  report socketPresent=false).
- start-agent-session.sh preflights the broker socket BEFORE any tmux
  effect (moved ahead of the ownership probe): absent -> exit 75
  (EX_TEMPFAIL), named refusal with socket path and remedy, no doomed
  pane. The agent@ unit is Type=oneshot with no Restart=, so the message
  survives instead of looping. The preflight detects and refuses; it
  never starts the broker.
- mosaic doctor's lease check names one convention-neutral remedy:
  'mosaic fleet install (it reconciles either enable convention)' —
  written from the measurement; teaching a manual systemctl line could
  leave a host with competing wants-symlinks.

Tests: fleet-place-unit.spec.ts (8: clean-host negative control,
by-path residue -> seed bytes AND mtime unchanged [the finding-2 check],
wants-residue cleared, idempotence single + double-install convergence);
fleet.spec.ts broker-first enable ordering, refused start emits no
holder/agent calls, second-start re-probe; reconciler broker plan member
(enabled-but-dead shape) + broker-before-agent ordering in both command
and apply paths; test-agent-session-broker-preflight.sh (CI-fit: fake
tmux, real unix socket at a short /tmp path — AF_UNIX caps at 108 bytes,
hermetic env; absent -> exit 75 + no tmux session, live socket passes,
explicit env wins, --stop not fenced). 1563/1563 vitest, lint, root
build 25/25, root typecheck 45/45.

Sabotage controls: placement unlink removed -> exactly the seed-integrity
test reddens (1/8); socket re-check disabled -> exactly the two preflight
specs redden; shell preflight removed -> the bash suite reddens (6 FAIL
assertions, rc=1). All restored byte-identically (sha256-verified), all
green again.

Test 6 (greenfield 1124, seat alive 2min + second fleet start) runs on
sandbox after daphne's baseline, coordinated with fred.

Note: the preflight uses exit 75 measured against the unit's Restart=
policy (oneshot, none) — no restart loop.
2026-08-17 18:38:22 -05:00
21 changed files with 995 additions and 1569 deletions
@@ -233,8 +233,36 @@ assert_owned_tmux_server() {
fail "tmux server ownership or environment validation failed"
}
# Validate exact server ownership before querying, cleaning, or creating any
# managed session. An unmanaged or contaminated named socket is never repaired.
# Lease-broker socket preflight (#1292). The gated runtime (`mosaic yolo …` →
# launch-runtime.py) registers with the broker or dies ~4 seconds in, with the
# diagnostic invisible because tmux destroys the dead pane. This check runs
# BEFORE any tmux effect — including the ownership probe below — so a host
# without a broker produces a named, surviving refusal instead of a doomed
# pane. Exit 75 (EX_TEMPFAIL), distinct from 64 (bad projection) and 69 (host
# not ready for other reasons); the agent@ unit is Type=oneshot with no
# Restart=, so the failed unit keeps its message instead of looping. Socket
# resolution matches launch.ts's defaultLeaseBrokerSocket precedence exactly.
# This preflight DETECTS and REFUSES — it never starts the broker (activation
# belongs to the fleet control plane; a component that both detects and fixes
# cannot be used to measure whether the fix worked).
broker_socket_path() {
if [ -n "${MOSAIC_LEASE_BROKER_SOCKET:-}" ]; then
printf '%s\n' "$MOSAIC_LEASE_BROKER_SOCKET"
return 0
fi
local runtime_dir="${XDG_RUNTIME_DIR:-/run/user/$(id -u)}"
printf '%s\n' "${runtime_dir}/mosaic-lease/broker.sock"
}
if [ "$MODE" = "launch" ]; then
_broker_socket=$(broker_socket_path)
if [ ! -S "$_broker_socket" ]; then
echo "[fleet] FAIL_LAUNCH broker-absent: lease broker socket ${_broker_socket} missing; runtime launch denied (#1292)." >&2
echo "[fleet] remedy: systemctl --user enable --now mosaic-lease-broker.service (or reinstall via: mosaic fleet install)" >&2
exit 75
fi
fi
assert_owned_tmux_server
if [ "$MODE" = interaction ]; then
@@ -0,0 +1,216 @@
#!/usr/bin/env bash
# CI-fit regression suite for the #1292 lease-broker socket preflight in
# start-agent-session.sh.
#
# WHY THIS SUITE IS CI-FIT WHERE test-start-agent-session.sh IS NOT (#1017/#1270
# context): that older suite's precondition is "the host does not have the pi
# binary", which a CI image that ships pi violates — its guard correctly
# refuses to report a pass there, so it is excluded from the chain. THIS suite
# controls its own preconditions instead of inheriting them from the host: a
# fake tmux on PATH, a fake mosaic on PATH, a real unix socket created in a
# tmpdir, a hermetic env (env -i, fake HOME, GIT_CONFIG_GLOBAL severed). It
# never depends on what the host has installed, so a green here means the same
# thing on every host. Anyone adding cases: keep that property — no case may
# depend on host state.
#
# The failure this suite is written down to catch (#1292): a seat launched on a
# host with no lease broker dies ~4 seconds in at registration, with the
# diagnostic invisible because tmux destroys the dead pane. The preflight runs
# BEFORE any tmux effect and refuses with a NAMED code (exit 75, EX_TEMPFAIL)
# so the message survives. The agent@ unit is Type=oneshot with no Restart=,
# so a failed unit keeps its output instead of looping.
#
# Cases:
# 1. absent socket -> exit 75, message names broker-absent + socket path +
# remedy, and NO tmux session was ever created (the doomed-pane half).
# 2. present socket (real unix socket in tmpdir) -> proceeds PAST the
# preflight (the suite then stops at the next precondition, proving the
# preflight was not the refusal).
# 3. explicit MOSAIC_LEASE_BROKER_SOCKET wins over XDG_RUNTIME_DIR default.
# 4. --stop mode does NOT require the broker (teardown must not be fenced on
# a component whose absence is exactly what teardown may follow).
#
# Sabotage control, run by the developer (not in-suite): remove the preflight
# block from start-agent-session.sh, re-run — case 1 fails (a tmux session is
# created / exit is not 75), cases 2-4 still pass; restore byte-identically.
set -euo pipefail
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
WORK_DIR="${MOSAIC_TEST_WORK_DIR:-$PWD/.mosaic-test-work/agent-session-broker-preflight}"
FAKE_HOME="$WORK_DIR/home"
BIN_DIR="$WORK_DIR/bin"
ENV_DIR="$WORK_DIR/env"
SOCK_DIR="$WORK_DIR/sockets"
LOG_FILE="$WORK_DIR/tmux-calls.log"
rm -rf "$WORK_DIR"
# The script asserts a managed directory tree under MOSAIC_HOME: mosaic/,
# mosaic/fleet/, mosaic/fleet/agents/ — private (0700/0750-style) modes, no
# symlinks — plus a per-agent env projection. Build the full tree the launcher
# expects so the suite reaches the BROKER preflight rather than dying at
# environment validation.
mkdir -p "$FAKE_HOME/.config/mosaic/fleet/agents" "$BIN_DIR" "$SOCK_DIR"
chmod 700 "$FAKE_HOME/.config/mosaic" "$FAKE_HOME/.config/mosaic/fleet/agents"
chmod 750 "$FAKE_HOME/.config/mosaic/fleet"
cat > "$FAKE_HOME/.config/mosaic/fleet/agents/preflight-test.env.generated" <<'ENVEOF'
MOSAIC_AGENT_NAME=preflight-test
MOSAIC_AGENT_CLASS=worker
MOSAIC_AGENT_RUNTIME=pi
MOSAIC_AGENT_MODEL=
MOSAIC_AGENT_REASONING=
MOSAIC_AGENT_TOOL_POLICY=code
MOSAIC_AGENT_WORKDIR=/tmp
MOSAIC_TMUX_SOCKET=mosaic-fleet
ENVEOF
chmod 600 "$FAKE_HOME/.config/mosaic/fleet/agents/preflight-test.env.generated"
# ─── Fake tmux: records every invocation; new-session marks the marker. ────
: > "$LOG_FILE"
cat > "$BIN_DIR/tmux" <<SH
#!/usr/bin/env bash
printf 'tmux %s\n' "\$*" >> "$LOG_FILE"
if [[ "\$*" == *new-session* ]]; then
echo "TMUX-NEW-SESSION-INVOKED" >> "$LOG_FILE"
fi
exit 0
SH
chmod +x "$BIN_DIR/tmux"
# ─── Fake mosaic/pi binaries so the script proceeds past its own lookups. ───
for bin in mosaic pi claude; do
printf '#!/usr/bin/env bash\nexit 0\n' > "$BIN_DIR/$bin"
chmod +x "$BIN_DIR/$bin"
done
# ─── Minimal launch environment the script expects. ────────────────────────
# (Enough for the preflight to be reached; later stages will still fail in
# case 2 — that is expected and asserted.)
run_session_script() {
local mode="$1"; shift
(
cd "$WORK_DIR"
env -i HOME="$FAKE_HOME" PATH="$BIN_DIR:/usr/bin:/bin" \
GIT_CONFIG_GLOBAL=/dev/null GIT_CONFIG_SYSTEM=/dev/null \
MOSAIC_HOME="$FAKE_HOME/.config/mosaic" \
AGENT_NAME=preflight-test \
"$@" \
bash "$SCRIPT_DIR/start-agent-session.sh" $mode preflight-test
)
}
fail=0
assert() {
local desc="$1" expected="$2" actual="$3"
if [[ "$expected" != "$actual" ]]; then
echo "FAIL: $desc — expected '$expected', got '$actual'" >&2
fail=1
fi
}
assert_contains() {
local desc="$1" haystack="$2" needle="$3"
[[ "$haystack" == *"$needle"* ]] || { echo "FAIL: $desc — missing '$needle' in: $haystack" >&2; fail=1; }
}
assert_not_contains() {
local desc="$1" haystack="$2" needle="$3"
if [[ "$haystack" == *"$needle"* ]]; then
echo "FAIL: $desc — must not contain '$needle'" >&2
fail=1
fi
return 0
}
# ─── 1. Absent socket → named refusal, NO tmux session. ────────────────────
: > "$LOG_FILE"
stderr_file="$WORK_DIR/stderr-1.tmp"
set +e
out=$(run_session_script "" MOSAIC_LEASE_BROKER_SOCKET="$SOCK_DIR/absent.sock" 2>"$stderr_file")
rc=$?
set -e
assert "absent socket exit code" "75" "$rc"
err=$(cat "$stderr_file")
assert_contains "absent socket names the failure" "$err" "FAIL_LAUNCH broker-absent"
assert_contains "absent socket names the socket path" "$err" "$SOCK_DIR/absent.sock"
assert_contains "absent socket names a remedy" "$err" "mosaic fleet install"
log1=$(cat "$LOG_FILE")
assert_not_contains "absent socket must not create a tmux session" "$log1" "TMUX-NEW-SESSION-INVOKED"
# ─── 2. Present socket → passes the preflight. ─────────────────────────────
# Expected: ownership/env checks AFTER the preflight may refuse (fixture is
# minimal by design); the assertion is only that the refusal is NOT
# broker-absent and the exit is NOT 75.
# Create a REAL unix socket: a detached python holder binds it and stays alive
# for the duration (bash cannot create sockets; a foreground python would
# close the socket on exit and -S on a closed-but-unlinked path fails). Written
# as a script file + setsid nohup so no job-control/heredoc interaction with
# set -e can silently kill the suite.
# AF_UNIX binds cap at 108 path bytes; the suite's workdir exceeds that, so
# the live socket lives at a SHORT path under /tmp (unique per run, cleaned
# with the suite). The preflight takes its socket path explicitly, so this
# stays fully controlled.
LIVE_SOCK=$(mktemp -u /tmp/mosaic-preflight-XXXXXX.sock)
trap 'rm -f "$LIVE_SOCK"' EXIT
rm -f "$SOCK_DIR/live.sock" "$LIVE_SOCK"
cat > "$SOCK_DIR/holder.py" <<'PY'
import socket, sys, time
path = sys.argv[1]
s = socket.socket(socket.AF_UNIX, socket.SOCK_STREAM)
s.bind(path)
s.listen(1)
time.sleep(120)
PY
python3 "$SOCK_DIR/holder.py" "$LIVE_SOCK" >/dev/null 2>"$SOCK_DIR/holder.err" &
HOLDER_PID=$!
# Wait for the socket object to exist (bind is near-instant, but do not race it).
for _ in $(seq 1 50); do
[ -S "$LIVE_SOCK" ] && break
sleep 0.1
done
if [ ! -S "$LIVE_SOCK" ]; then
echo "FAIL: could not create live socket fixture (holder pid $HOLDER_PID)" >&2
ps -p "$HOLDER_PID" -o pid,stat,cmd --no-headers >&2 || echo "(holder exited)" >&2
cat "$SOCK_DIR/holder.err" >&2 || true
exit 1
fi
: > "$LOG_FILE"
set +e
out=$(run_session_script "" MOSAIC_LEASE_BROKER_SOCKET="$LIVE_SOCK" 2>"$WORK_DIR/stderr-2.tmp")
rc=$?
set -e
# The preflight PASSED if the failure (whatever later stage refused) is NOT
# the broker refusal, and tmux was reached or a later precondition named
# something else.
err2=$(cat "$WORK_DIR/stderr-2.tmp")
assert_not_contains "live socket must not refuse broker-absent" "$err2" "broker-absent"
if [[ "$rc" == "75" ]]; then
echo "FAIL: live socket — preflight still refused (exit 75) with a live socket" >&2
fail=1
fi
# ─── 3. Explicit socket env wins over XDG default. ─────────────────────────
set +e
out=$(run_session_script "" XDG_RUNTIME_DIR="$SOCK_DIR/no-runtime-here" MOSAIC_LEASE_BROKER_SOCKET="$SOCK_DIR/absent2.sock" 2>"$WORK_DIR/stderr-3.tmp")
rc=$?
set -e
assert "explicit env wins (exit 75)" "75" "$rc"
assert_contains "explicit env path named" "$(cat "$WORK_DIR/stderr-3.tmp")" "$SOCK_DIR/absent2.sock"
# ─── 4. --stop is not fenced on the broker. ────────────────────────────────
: > "$LOG_FILE"
set +e
out=$(run_session_script "--stop" MOSAIC_LEASE_BROKER_SOCKET="$SOCK_DIR/absent3.sock" 2>"$WORK_DIR/stderr-4.tmp")
rc=$?
set -e
err4=$(cat "$WORK_DIR/stderr-4.tmp")
assert_not_contains "--stop must not refuse broker-absent" "$err4" "broker-absent"
if [[ "$rc" == "75" ]]; then
echo "FAIL: --stop — exit 75 means teardown was fenced on the broker" >&2
fail=1
fi
kill "$HOLDER_PID" 2>/dev/null || true
if [[ "$fail" -eq 0 ]]; then
echo "start-agent-session lease-broker preflight regression passed"
fi
exit "$fail"
@@ -0,0 +1,177 @@
import { lstat, mkdir, mkdtemp, readFile, rm, symlink, writeFile } from 'node:fs/promises';
import { tmpdir } from 'node:os';
import { join } from 'node:path';
import { afterEach, describe, expect, it } from 'vitest';
import { placeUnitFile, resolveLeaseBrokerSocketForPreflight } from './fleet.js';
/**
* Unit-placement regression harness for #1292.
*
* The two measured defects this suite pins:
* 1. `systemctl enable <name>` does NOT rewrite an existing by-path
* wants-symlink — so placement must remove stale residue explicitly, and
* acceptance asserts on the RESULTING SYMLINK TARGET, never on the enable
* call's argument (asserting the call cannot see where the link ended up).
* 2. Node's copyFile FOLLOWS a by-path symlink at the destination and
* overwrites the SEED template. Acceptance asserts on the SEED's bytes
* AND mtime — unchanged — which is the only check that can redden for
* finding 2. The symlink-target assertion catches finding 1; these are
* different defects with different failure modes.
*
* Fixtures are entirely inside tmpdirs (source template, active systemd dir,
* wants dir) — no real host paths are touched by this suite.
*/
describe('placeUnitFile (#1292 unit placement)', () => {
const cleanup: string[] = [];
afterEach(async () => {
while (cleanup.length > 0) {
await rm(cleanup.pop()!, { recursive: true, force: true });
}
});
async function fixture() {
const root = await mkdtemp(join(tmpdir(), 'place-unit-'));
cleanup.push(root);
const seedDir = join(root, 'seed');
const activeDir = join(root, 'active');
await mkdir(seedDir, { recursive: true });
await mkdir(activeDir, { recursive: true });
const seedTemplate = join(seedDir, 'unit-under-test.service');
await writeFile(
seedTemplate,
'[Unit]\nDescription=seed template\n[Service]\nType=oneshot\nExecStart=/bin/true\n[Install]\nWantedBy=default.target\n',
);
const activeSource = join(root, 'active-source.service');
await writeFile(
activeSource,
'[Unit]\nDescription=active copy v2\n[Service]\nType=oneshot\nExecStart=/bin/true\n[Install]\nWantedBy=default.target\n',
);
return { root, seedDir, activeDir, seedTemplate, activeSource };
}
it('places a regular file on a clean host (negative control: no residue anywhere)', async () => {
const f = await fixture();
const result = await placeUnitFile(f.activeSource, f.activeDir, 'unit-under-test.service');
expect(result.unlinkedDestinationSymlink).toBe(false);
expect(result.removedStaleWantsSymlink).toBe(false);
const info = await lstat(join(f.activeDir, 'unit-under-test.service'));
expect(info.isSymbolicLink()).toBe(false);
expect(await readFile(join(f.activeDir, 'unit-under-test.service'), 'utf8')).toContain(
'active copy v2',
);
// Seed untouched by construction — but assert it, so the clean-host case
// cannot silently regress into seed-mutation.
expect(await readFile(f.seedTemplate, 'utf8')).toContain('seed template');
});
it('by-path residue: unlinks destination symlink, places the file, seed bytes AND mtime unchanged (finding 2)', async () => {
const f = await fixture();
const seedBefore = await readFile(f.seedTemplate, 'utf8');
const mtimeBefore = (await lstat(f.seedTemplate)).mtimeMs;
// The fomo-lin convention: by-path enable left a symlink AT the unit name
// pointing at the seed template, plus a wants-symlink doing the same.
await symlink(f.seedTemplate, join(f.activeDir, 'unit-under-test.service'));
const wantsDir = join(f.activeDir, 'default.target.wants');
await mkdir(wantsDir, { recursive: true });
await symlink(f.seedTemplate, join(wantsDir, 'unit-under-test.service'));
const result = await placeUnitFile(f.activeSource, f.activeDir, 'unit-under-test.service');
expect(result.unlinkedDestinationSymlink).toBe(true);
expect(result.removedStaleWantsSymlink).toBe(true);
// FINDING 2's check: the seed is byte-identical and its mtime did not move.
expect(await readFile(f.seedTemplate, 'utf8')).toBe(seedBefore);
expect((await lstat(f.seedTemplate)).mtimeMs).toBe(mtimeBefore);
// The destination is now a regular file carrying the ACTIVE content.
const destInfo = await lstat(join(f.activeDir, 'unit-under-test.service'));
expect(destInfo.isSymbolicLink()).toBe(false);
expect(await readFile(join(f.activeDir, 'unit-under-test.service'), 'utf8')).toContain(
'active copy v2',
);
});
it('by-path residue: no wants-symlink remains pointing at the seed (finding 1 residue cleared)', async () => {
const f = await fixture();
await symlink(f.seedTemplate, join(f.activeDir, 'unit-under-test.service'));
const wantsDir = join(f.activeDir, 'default.target.wants');
await mkdir(wantsDir, { recursive: true });
await symlink(f.seedTemplate, join(wantsDir, 'unit-under-test.service'));
await placeUnitFile(f.activeSource, f.activeDir, 'unit-under-test.service');
// After placement the stale wants link is GONE (enable-by-name recreates
// it correctly). A link still present must not point at the seed.
try {
const link = await lstat(join(wantsDir, 'unit-under-test.service'));
if (link.isSymbolicLink()) {
const target = await readFile(join(wantsDir, 'unit-under-test.service'), 'utf8').catch(
async () => '',
);
expect(target).not.toContain('seed template');
}
} catch {
// absent wants link — the expected post-placement state
}
});
it('idempotence: second placement on a reconciled host is a no-op producing the identical final state', async () => {
const f = await fixture();
// Reconciled starting state: regular file at the name, wants link to the active copy.
await writeFile(
join(f.activeDir, 'unit-under-test.service'),
await readFile(f.activeSource, 'utf8'),
);
const wantsDir = join(f.activeDir, 'default.target.wants');
await mkdir(wantsDir, { recursive: true });
await symlink(
join(f.activeDir, 'unit-under-test.service'),
join(wantsDir, 'unit-under-test.service'),
);
const before = await readFile(join(f.activeDir, 'unit-under-test.service'), 'utf8');
const result = await placeUnitFile(f.activeSource, f.activeDir, 'unit-under-test.service');
// No destructive step fired: no unlink, no wants removal.
expect(result.unlinkedDestinationSymlink).toBe(false);
expect(result.removedStaleWantsSymlink).toBe(false);
// Identical final state.
expect(await readFile(join(f.activeDir, 'unit-under-test.service'), 'utf8')).toBe(before);
const link = await lstat(join(wantsDir, 'unit-under-test.service'));
expect(link.isSymbolicLink()).toBe(true);
});
it('double install on by-path residue converges to the identical reconciled state', async () => {
const f = await fixture();
await symlink(f.seedTemplate, join(f.activeDir, 'unit-under-test.service'));
const wantsDir = join(f.activeDir, 'default.target.wants');
await mkdir(wantsDir, { recursive: true });
await symlink(f.seedTemplate, join(wantsDir, 'unit-under-test.service'));
await placeUnitFile(f.activeSource, f.activeDir, 'unit-under-test.service');
const first = await readFile(join(f.activeDir, 'unit-under-test.service'), 'utf8');
const secondRun = await placeUnitFile(f.activeSource, f.activeDir, 'unit-under-test.service');
const second = await readFile(join(f.activeDir, 'unit-under-test.service'), 'utf8');
expect(secondRun.unlinkedDestinationSymlink).toBe(false);
expect(second).toBe(first);
});
});
describe('resolveLeaseBrokerSocketForPreflight (#1292 preflight resolution)', () => {
it('explicit MOSAIC_LEASE_BROKER_SOCKET wins', () => {
expect(
resolveLeaseBrokerSocketForPreflight({ MOSAIC_LEASE_BROKER_SOCKET: '/custom/sock' }, 1000),
).toBe('/custom/sock');
});
it('XDG_RUNTIME_DIR next', () => {
expect(resolveLeaseBrokerSocketForPreflight({ XDG_RUNTIME_DIR: '/run/user/1001' }, 1000)).toBe(
'/run/user/1001/mosaic-lease/broker.sock',
);
});
it('falls back to /run/user/<uid>', () => {
expect(resolveLeaseBrokerSocketForPreflight({}, 1002)).toBe(
'/run/user/1002/mosaic-lease/broker.sock',
);
});
});
+110 -1
View File
@@ -835,13 +835,25 @@ describe('fleet command construction', () => {
};
const program = new Command();
program.exitOverride();
registerFleetCommand(program, { runner, mosaicHome: home });
// #1292: inject a present broker socket so the preflight passes and this
// spec keeps testing its ORIGINAL property (holder-before-agent ordering).
// The preflight's own refusal behavior has dedicated specs below.
registerFleetCommand(program, {
runner,
mosaicHome: home,
checkBrokerSocket: async () => true,
});
try {
await program.parseAsync(['node', 'mosaic', 'fleet', 'start']);
await program.parseAsync(['node', 'mosaic', 'fleet', 'stop']);
expect(calls).toEqual([
// #1292: fleet start enables + starts the broker FIRST (enable is
// idempotent; the unit exists after install), re-checking the socket
// before any holder/agent lifecycle effect.
['systemctl', '--user', 'enable', 'mosaic-lease-broker.service'],
['systemctl', '--user', 'start', 'mosaic-lease-broker.service'],
['systemctl', '--user', 'start', 'mosaic-tmux-holder.service'],
['systemctl', '--user', 'start', '[email protected]'],
['systemctl', '--user', 'stop', '[email protected]'],
@@ -852,6 +864,92 @@ describe('fleet command construction', () => {
}
});
it('fleet start refuses with a named error when the broker socket does not appear (#1292)', async () => {
const home = await tempDir();
const rosterPath = join(home, 'fleet', 'roster.yaml');
await mkdir(join(home, 'fleet'), { recursive: true });
await writeFile(
rosterPath,
['version: 1', 'transport: tmux', 'agents:', ' - name: coder0', ' runtime: codex'].join(
'\n',
),
);
const calls: string[][] = [];
const runner: CommandRunner = async (command, args) => {
calls.push([command, ...args]);
return { stdout: '', stderr: '', exitCode: 0 };
};
const program = new Command();
program.exitOverride();
const errors: string[] = [];
const origError = console.error;
console.error = (...args: unknown[]) => {
errors.push(args.join(' '));
};
registerFleetCommand(program, {
runner,
mosaicHome: home,
checkBrokerSocket: async () => false,
});
try {
await program.parseAsync(['node', 'mosaic', 'fleet', 'start']);
// Refused: no holder/agent starts were issued after the broker attempt.
expect(calls).toEqual([
['systemctl', '--user', 'enable', 'mosaic-lease-broker.service'],
['systemctl', '--user', 'start', 'mosaic-lease-broker.service'],
]);
expect(errors.join('\n')).toContain('broker-absent');
expect(errors.join('\n')).toContain('mosaic fleet install');
} finally {
console.error = origError;
await rm(home, { recursive: true, force: true });
}
});
it('fleet start re-probes the broker on the SECOND invocation — no ActiveState trust (#1292 sticky half)', async () => {
const home = await tempDir();
const rosterPath = join(home, 'fleet', 'roster.yaml');
await mkdir(join(home, 'fleet'), { recursive: true });
await writeFile(
rosterPath,
['version: 1', 'transport: tmux', 'agents:', ' - name: coder0', ' runtime: codex'].join(
'\n',
),
);
const calls: string[][] = [];
const runner: CommandRunner = async (command, args) => {
calls.push([command, ...args]);
return { stdout: '', stderr: '', exitCode: 0 };
};
const program = new Command();
program.exitOverride();
// Broker socket NEVER appears — the second start must refuse exactly like
// the first; RemainAfterExit-style stale unit state changes nothing
// because the check is the socket, not systemctl.
registerFleetCommand(program, {
runner,
mosaicHome: home,
checkBrokerSocket: async () => false,
});
const errors: string[] = [];
const origError = console.error;
console.error = (...args: unknown[]) => {
errors.push(args.join(' '));
};
try {
await program.parseAsync(['node', 'mosaic', 'fleet', 'start']);
await program.parseAsync(['node', 'mosaic', 'fleet', 'start']);
// Two invocations, each refusing after its own broker attempt:
expect(
calls.filter((c) => c.join(' ') === 'systemctl --user start [email protected]'),
).toHaveLength(0);
expect(errors.filter((e) => e.includes('broker-absent')).length).toBeGreaterThanOrEqual(2);
} finally {
console.error = origError;
await rm(home, { recursive: true, force: true });
}
});
it('waits for an in-flight restart to clear before relaunching (re-entry guard)', async () => {
const home = await tempDir();
const rosterPath = join(home, 'fleet', 'roster.yaml');
@@ -2065,8 +2163,19 @@ describe('fleet install — auto-enable units for boot-survival', () => {
await enableFleetUnits(runner, minimalRoster, {});
expect(calls).toContainEqual(['systemctl', '--user', 'enable', 'mosaic-lease-broker.service']);
expect(calls).toContainEqual(['systemctl', '--user', 'enable', 'mosaic-tmux-holder.service']);
expect(calls).toContainEqual(['systemctl', '--user', 'enable', '[email protected]']);
// The broker must be enabled BEFORE the holder and agents: a start of any
// gated runtime without the broker is exactly the #1292 4-second death.
const brokerIndex = calls.findIndex(
(c) => c.join(' ') === 'systemctl --user enable mosaic-lease-broker.service',
);
const holderIndex = calls.findIndex(
(c) => c.join(' ') === 'systemctl --user enable mosaic-tmux-holder.service',
);
expect(brokerIndex).toBeGreaterThanOrEqual(0);
expect(brokerIndex).toBeLessThan(holderIndex);
});
it('install still succeeds when systemctl enable returns non-zero (non-fatal)', async () => {
+214 -13
View File
@@ -3,9 +3,11 @@ import {
access,
chmod,
copyFile,
lstat,
mkdir,
open,
readFile,
readlink,
stat,
unlink,
writeFile,
@@ -89,6 +91,8 @@ export type SleepFn = (ms: number) => Promise<void>;
export interface FleetCommandDeps {
runner?: CommandRunner;
/** Test seam for the #1292 fleet-start broker preflight (socket presence). */
checkBrokerSocket?: (path: string) => Promise<boolean> | boolean;
/** Injectable interactive runner for commands needing inherited TTY (e.g., `tmux attach`). */
interactiveRunner?: InteractiveRunner;
/**
@@ -797,6 +801,96 @@ export function buildSystemdEnableCommand(unit: string): string[] {
return ['systemctl', '--user', 'enable', unit];
}
/**
* Place a unit file into the ACTIVE systemd user directory, never through a
* symlink (#1292, measured 2026-08-17).
*
* ⚠ SET-INDEPENDENCE (fomo-lin, 2026-08-17): the set of unit names carrying
* by-path residue and the set of unit names this install copies are
* INDEPENDENT. Until 0.0.50 they were disjoint only by accident of which
* units the install happened to name — fomo-lin survived copy-through solely
* because its one by-path symlink (the broker) was the one unit the install
* did NOT copy. Adding the broker to the copy set made the intersection
* non-empty on the first run. Whoever adds a fifth unit to the placement
* list inherits this helper and its unlink step; do not place units with a
* bare copyFile.
*
* A host provisioned by the enable-by-path convention carries a symlink AT
* the unit-name path in ~/.config/systemd/user/ pointing at the shipped
* template under ~/.config/mosaic/systemd/user/. Node's copyFile FOLLOWS
* that link and overwrites the SEED template instead of placing the active
* unit (verified with fs.copyFile on a throwaway systemd user instance) —
* silent, rc=0, and it mutates the directory every later reseed reads from.
* The same measurement showed `systemctl enable <name>` does NOT rewrite an
* existing by-path wants-symlink, so reconciliation must be explicit.
*
* Placement therefore: if the destination is a symlink, unlink it first
* (unlink → copy — copy-then-unlink would mutate the seed and then destroy
* the evidence that it did); then copy. Also removes a stale
* `default.target.wants/<name>` symlink that points outside the active
* directory (readlink — NOT readFile, which follows the link and returns the
* target's CONTENT), so the subsequent enable-by-name recreates it against
* the active copy. Idempotent: on a clean or already-reconciled destination
* every step is a no-op (the copy rewrites identical bytes).
*
* Returns what was done, for assertions and install reporting.
*/
export interface PlaceUnitResult {
readonly unit: string;
readonly destination: string;
/** A symlink at the unit-name path was unlinked (by-path residue). */
readonly unlinkedDestinationSymlink: boolean;
/** A stale wants-symlink pointing outside the active dir was removed. */
readonly removedStaleWantsSymlink: boolean;
}
export async function placeUnitFile(
source: string,
systemdUserDir: string,
unit: string,
): Promise<PlaceUnitResult> {
const destination = join(systemdUserDir, unit);
let unlinkedDestinationSymlink = false;
try {
const destInfo = await lstat(destination);
if (destInfo.isSymbolicLink()) {
await unlink(destination);
unlinkedDestinationSymlink = true;
}
} catch {
// absent destination — nothing to unlink
}
await copyFile(source, destination);
let removedStaleWantsSymlink = false;
const wantsLink = join(systemdUserDir, 'default.target.wants', unit);
try {
const wantsInfo = await lstat(wantsLink);
if (wantsInfo.isSymbolicLink()) {
// readlink — NOT readFile: readFile FOLLOWS the link and returns the
// target file's CONTENT, which is not the question being asked.
let target: string | undefined;
try {
target = await readlink(wantsLink);
} catch {
target = undefined;
}
// Normalize (systemctl writes absolute targets; a relative one resolves
// against the wants dir). A wants-symlink pointing anywhere other than
// the active copy (the by-path convention points at the seed template)
// survives enable-by-name unchanged — remove it so enable recreates it.
if (target !== undefined && resolve(dirname(wantsLink), target) !== destination) {
await unlink(wantsLink);
removedStaleWantsSymlink = true;
}
}
} catch {
// absent wants link — nothing to reconcile
}
return { unit, destination, unlinkedDestinationSymlink, removedStaleWantsSymlink };
}
/**
* Returns the systemctl --user disable command for a given unit.
* Used by `fleet remove` so a removed agent's enabled unit cannot resurrect on
@@ -831,6 +925,22 @@ export async function enableFleetUnits(
let succeeded = 0;
let failed = 0;
// The lease broker ships with the fleet and every gated runtime needs it
// (#1292): seats die at lease registration without it, and no documented
// path ever enabled it. Enabled first — alongside the holder — and the
// unit must have been placed by installFleet's placeUnitFile step.
const brokerResult = await runner(
...splitCommand(buildSystemdEnableCommand('mosaic-lease-broker.service')),
);
if (brokerResult.exitCode === 0) {
succeeded++;
} else {
failed++;
process.stderr.write(
`Warning: could not enable mosaic-lease-broker.service: ${brokerResult.stderr || brokerResult.stdout || 'non-zero exit'}\n`,
);
}
const holderResult = await runner(
...splitCommand(buildSystemdEnableCommand('mosaic-tmux-holder.service')),
);
@@ -1527,7 +1637,7 @@ export function registerFleetCommand(program: Command, deps: FleetCommandDeps =
.description('Install local fleet tools and user systemd units')
.option('--no-enable', 'Skip enabling units for boot-survival')
.action(async (opts: { enable?: boolean }) => {
await installFleet(cmd, frameworkRoot);
await installFleet(cmd, frameworkRoot, runner);
// Unit enablement needs agent names only, so it reads either version.
const roster = await loadRosterReadModel(cmd);
await enableFleetUnits(runner, roster, opts);
@@ -1538,7 +1648,7 @@ export function registerFleetCommand(program: Command, deps: FleetCommandDeps =
.description('Install local fleet tools and user systemd units')
.option('--no-enable', 'Skip enabling units for boot-survival')
.action(async (opts: { enable?: boolean }) => {
await installFleet(cmd, frameworkRoot);
await installFleet(cmd, frameworkRoot, runner);
// Unit enablement needs agent names only, so it reads either version.
const roster = await loadRosterReadModel(cmd);
await enableFleetUnits(runner, roster, opts);
@@ -1591,6 +1701,37 @@ export function registerFleetCommand(program: Command, deps: FleetCommandDeps =
);
return;
}
if (action === 'start') {
// Broker preflight (#1292), re-probed on EVERY invocation: a
// gated runtime started without a live lease broker dies ~4s in
// while the unit reports active (RemainAfterExit) — enabling +
// starting here and then RE-CHECKING the socket refuses loudly
// instead of reporting rc0 over a doomed start. This is the
// second-start check as much as the first: it never trusts unit
// ActiveState.
await runChecked(runner, [
'systemctl',
'--user',
'enable',
'mosaic-lease-broker.service',
]);
await runChecked(runner, [
'systemctl',
'--user',
'start',
'mosaic-lease-broker.service',
]);
if (!(await brokerSocketPresent(deps))) {
console.error(
'[fleet] broker-absent: lease broker socket did not appear after enable+start (#1292).',
);
console.error(
'[fleet] remedy: mosaic fleet install (it reconciles either enable convention)',
);
process.exitCode = 1;
return;
}
}
if (action === 'restart') {
// Serialize the holder+agents teardown/relaunch behind the restart lock
// so a re-entrant restart waits for clean shutdown before relaunching,
@@ -2349,7 +2490,11 @@ export function registerFleetAgentCommands(
});
}
async function installFleet(cmd: Command, frameworkRoot: string): Promise<void> {
async function installFleet(
cmd: Command,
frameworkRoot: string,
runner: CommandRunner,
): Promise<void> {
const activePaths = resolveFleetPaths(cmd.opts<{ mosaicHome: string }>().mosaicHome);
assertDefaultMosaicHomeForSystemd(activePaths.mosaicHome);
// Read model first: every file this function places is roster-independent, and
@@ -2401,18 +2546,40 @@ async function installFleet(cmd: Command, frameworkRoot: string): Promise<void>
for (const toolPath of executableToolPaths) {
await chmod(toolPath, 0o755);
}
await copyFile(
join(frameworkRoot, 'systemd', 'user', 'mosaic-tmux-holder.service'),
join(activePaths.systemdUserDir, 'mosaic-tmux-holder.service'),
// Unit placement (#1292): every unit goes through placeUnitFile — never a
// bare copyFile — so a by-path-enable symlink at the destination is
// unlinked rather than written through (copy-through would silently
// overwrite the SEED template, measured 2026-08-17). The lease broker unit
// is placed here too: previously the install named three units and omitted
// the broker entirely, which is why no documented path ever enabled it.
const placedUnits = await Promise.all(
[
'mosaic-tmux-holder.service',
'[email protected]',
'[email protected]',
'mosaic-lease-broker.service',
].map((unit) =>
placeUnitFile(join(frameworkRoot, 'systemd', 'user', unit), activePaths.systemdUserDir, unit),
),
);
await copyFile(
join(frameworkRoot, 'systemd', 'user', '[email protected]'),
join(activePaths.systemdUserDir, '[email protected]'),
);
await copyFile(
join(frameworkRoot, 'systemd', 'user', '[email protected]'),
join(activePaths.systemdUserDir, '[email protected]'),
const reconciled = placedUnits.filter(
(result) => result.unlinkedDestinationSymlink || result.removedStaleWantsSymlink,
);
if (reconciled.length > 0) {
console.log(
`Reconciled ${reconciled.length} unit placement(s) from by-path enable residue: ${reconciled.map((r) => r.unit).join(', ')}`,
);
}
// systemd will not see a replaced unit file without a reload; do it once
// after all placements, before any enable call below. runCommand never
// rejects (it resolves exitCode 127 on spawn error), so a plain await with
// an exitCode check matches the rest of this file's systemctl handling.
const reloadResult = await runner(...splitCommand(['systemctl', '--user', 'daemon-reload']));
if (reloadResult.exitCode !== 0) {
process.stderr.write(
`Warning: systemctl --user daemon-reload after unit placement failed (non-systemd host?): ${reloadResult.stderr || reloadResult.stdout || 'non-zero exit'}\n`,
);
}
// On roster v2 the reconciler owns the generated env: `apply` writes it and
// `regen` rebuilds it, both from projectRosterV2AgentGeneratedEnv. Writing it
@@ -2609,6 +2776,40 @@ function splitCommand(command: string[]): [string, string[]] {
return [bin, args];
}
/**
* Lease-broker socket presence for the fleet-start preflight (#1292).
* Resolution precedence matches launch.ts's defaultLeaseBrokerSocket and
* start-agent-session.sh's broker_socket_path: explicit
* MOSAIC_LEASE_BROKER_SOCKET, else $XDG_RUNTIME_DIR/mosaic-lease/broker.sock,
* else /run/user/<uid>/mosaic-lease/broker.sock. Pure filesystem check — this
* deliberately does NOT consult systemd state: a unit can be active
* (RemainAfterExit) with no live socket, and the socket is the thing the
* gated runtime connects to. Injectable via deps for tests.
*/
export function resolveLeaseBrokerSocketForPreflight(
env: NodeJS.ProcessEnv = process.env,
uid: number = typeof process.getuid === 'function' ? process.getuid() : 0,
): string {
if (env['MOSAIC_LEASE_BROKER_SOCKET']) return env['MOSAIC_LEASE_BROKER_SOCKET'];
const runtimeDir = env['XDG_RUNTIME_DIR'] ?? `/run/user/${uid}`;
return join(runtimeDir, 'mosaic-lease', 'broker.sock');
}
async function brokerSocketPresent(
deps: FleetCommandDeps,
env: NodeJS.ProcessEnv = process.env,
): Promise<boolean> {
const check = deps.checkBrokerSocket;
if (check) return check(resolveLeaseBrokerSocketForPreflight(env));
try {
const socketPath = resolveLeaseBrokerSocketForPreflight(env);
await access(socketPath, constants.S_IFSOCK);
return true;
} catch {
return false;
}
}
/** All supported fleet profile names. */
export type FleetProfile =
| 'general'
@@ -205,6 +205,12 @@ export async function runLeaseEnforcementDoctorCheck(
message:
`Lease-enforcement hooks (${matchedMarkers.join(', ')}) are wired in ~/.claude/settings.json, but ${reasons.join(' and ')}. ` +
'Every gated tool call will fail closed and BRICK this agent (see #869). ' +
'Remediate by activating the lease-broker supervisor (systemd unit + socket) or by removing the enforcement hooks from ~/.claude/settings.json.',
// #1292: one remedy, correct under BOTH enable conventions (by-path on
// the seed template, and copy-then-enable in the active dir). Written
// from the 2026-08-17 symlink measurement: `systemctl enable` by name
// does NOT rewrite an existing by-path wants-symlink, so teaching a
// manual systemctl line here could leave a host with two competing
// wants links. fleet install reconciles either shape.
'Remedy: run `mosaic fleet install` (it reconciles either enable convention), or remove the enforcement hooks from ~/.claude/settings.json.',
};
}
@@ -1,149 +0,0 @@
import { mkdtemp, readFile, readdir } from 'node:fs/promises';
import os from 'node:os';
import path from 'node:path';
import { parse as parseYaml } from 'yaml';
import { Command } from 'commander';
import { afterEach, beforeEach, describe, expect, it, vi } from 'vitest';
import { registerMissionCommand } from './mission.js';
import { PrdService } from '@mosaicstack/prdy';
import type { MissionInfo } from '../tui/gateway-api.js';
// ── Mocks: the gateway is not available in adapter tests ──────────────────────
// vi.hoisted: the mock factory is hoisted above imports, so the fixture must
// be initialized there too.
const MISSION = vi.hoisted(
(): MissionInfo => ({
id: 'mission-plan-1',
name: 'Plan Mission Alpha',
description: null,
status: 'planning',
projectId: null,
userId: null,
phase: null,
milestones: null,
config: null,
createdAt: '2026-01-01T00:00:00.000Z',
updatedAt: '2026-03-04T05:06:07.000Z',
}),
);
vi.mock('./with-auth.js', () => ({
withAuth: vi.fn().mockResolvedValue({
gateway: 'http://localhost:14242',
cookie: 'better-auth.session_token=test',
session: {},
}),
}));
vi.mock('../tui/gateway-api.js', () => ({
fetchMissions: vi.fn().mockResolvedValue([MISSION]),
fetchMission: vi.fn(),
createMission: vi.fn(),
updateMission: vi.fn(),
fetchMissionTasks: vi.fn().mockResolvedValue([]),
createMissionTask: vi.fn(),
updateMissionTask: vi.fn(),
fetchProjects: vi.fn().mockResolvedValue([]),
}));
// ── Helpers ──────────────────────────────────────────────────────────────────
const originalCwd = process.cwd();
let projectDir: string;
let logSpy: ReturnType<typeof vi.spyOn>;
let consoleStub: ReturnType<typeof vi.spyOn>[] = [];
function buildTestProgram(): Command {
const program = new Command('mosaic').exitOverride();
registerMissionCommand(program);
return program;
}
beforeEach(async () => {
projectDir = await mkdtemp(path.join(os.tmpdir(), 'mosaic-mission-plan-'));
process.chdir(projectDir);
logSpy = vi.spyOn(console, 'log').mockImplementation(() => {});
consoleStub.push(logSpy);
});
afterEach(() => {
// Restore only the per-test spies; module factory mocks keep their
// implementations across tests.
for (const stub of consoleStub) stub.mockRestore();
consoleStub = [];
process.chdir(originalCwd);
});
// ── Tests ────────────────────────────────────────────────────────────────────
describe('mosaic mission --plan (thin adapter over PrdService)', () => {
it('creates the PRD in the shared docs/prdy authority store and persists the mission linkage', async () => {
await buildTestProgram().parseAsync(['mission', '--plan', 'Plan Mission Alpha'], {
from: 'user',
});
// PRD landed in the same store `mosaic prdy` uses.
const files = await readdir(path.join(projectDir, 'docs', 'prdy'));
expect(files).toHaveLength(1);
expect(files[0]).toMatch(/\.yaml$/);
// Fresh service instance (new-process equivalent) reads the linkage back.
const service = new PrdService({ projectPath: projectDir });
const docs = await service.list();
expect(docs).toHaveLength(1);
const prd = docs[0]!;
expect(prd.title).toBe('Plan Mission Alpha');
expect(prd.version).toBe(1);
const links = await service.listMissionLinks(prd.id);
expect(links).toHaveLength(1);
expect(links[0]).toMatchObject({
missionId: MISSION.id,
missionVersion: MISSION.updatedAt, // mission version marker
prdVersion: 1,
});
expect(logSpy).toHaveBeenCalledWith(expect.stringContaining('PRD created and linked'));
});
it('linkage is persisted in the YAML authority document itself (survives restart)', async () => {
await buildTestProgram().parseAsync(['mission', '--plan', 'Plan Mission Alpha'], {
from: 'user',
});
const files = await readdir(path.join(projectDir, 'docs', 'prdy'));
const raw = await readFile(path.join(projectDir, 'docs', 'prdy', files[0]!), 'utf8');
const persisted = parseYaml(raw) as { missions: Array<Record<string, unknown>> };
expect(persisted.missions).toHaveLength(1);
expect(persisted.missions[0]).toMatchObject({ missionId: 'mission-plan-1' });
});
it('the mission path and the prdy path resolve to the same store with stable ids/versions', async () => {
// Mission path.
await buildTestProgram().parseAsync(['mission', '--plan', 'Plan Mission Alpha'], {
from: 'user',
});
// prdy path (service, non-interactive entry).
const service = new PrdService({ projectPath: projectDir });
const direct = await service.create({ name: 'Directly Created' });
const all = await service.list();
expect(all.map((doc) => doc.id).sort()).toEqual([...all.map((doc) => doc.id)].sort());
expect(all).toHaveLength(2);
const files = await readdir(path.join(projectDir, 'docs', 'prdy'));
expect(files).toContain(`${direct.id}.yaml`);
// Both are v1 in the same store with distinct stable ids.
for (const doc of all) {
expect(doc.version).toBe(1);
expect(files).toContain(`${doc.id}.yaml`);
}
});
});
+5 -32
View File
@@ -256,41 +256,14 @@ async function planMission(
console.log(`Planning mission: ${mission.name}\n`);
try {
// Thin adapter: the PRD authority (create + mission↔PRD linkage) lives in
// PrdService — no second writer path. The mission's updatedAt serves as
// its version marker (the gateway exposes no numeric mission version).
const { PrdService, runPrdWizard } = await import('@mosaicstack/prdy');
const service = new PrdService({ projectPath: process.cwd() });
if (process.stdout.isTTY) {
const created = await runPrdWizard({
name: mission.name,
projectPath: process.cwd(),
interactive: true,
});
const linked = await service.linkMission({
prdId: created.id,
missionId: mission.id,
missionVersion: mission.updatedAt,
requirementIds: [],
});
console.log(
`\nMission ${mission.id} linked to PRD ${linked.id} v${linked.version} (docs/prdy/).`,
);
return;
}
const doc = await service.planForMission({
const { runPrdWizard } = await import('@mosaicstack/prdy');
await runPrdWizard({
name: mission.name,
missionId: mission.id,
missionVersion: mission.updatedAt,
requirementIds: [],
projectPath: process.cwd(),
interactive: true,
});
console.log(
`PRD created and linked: ${doc.id} v${doc.version} — mission ${mission.id} (docs/prdy/).`,
);
} catch (err) {
console.error(`PRD planning failed: ${err instanceof Error ? err.message : String(err)}`);
console.error(`PRD wizard failed: ${err instanceof Error ? err.message : String(err)}`);
process.exit(1);
}
}
-204
View File
@@ -1,204 +0,0 @@
import { mkdtemp, readFile, readdir, writeFile } from 'node:fs/promises';
import os from 'node:os';
import path from 'node:path';
import { stringify as stringifyYaml } from 'yaml';
import { Command } from 'commander';
import { afterEach, beforeEach, describe, expect, it, vi } from 'vitest';
import { registerPrdyCommand } from './prdy.js';
import { PrdService } from '@mosaicstack/prdy';
// ── Mocks: keep the adapter test offline (no gateway, no disk side effects
// outside the tmp project dir) ──────────────────────────────────────────────
vi.mock('./with-auth.js', () => ({
withAuth: vi.fn().mockResolvedValue({
gateway: 'http://localhost:14242',
cookie: 'better-auth.session_token=test',
session: {},
}),
}));
vi.mock('../tui/gateway-api.js', () => ({
fetchProjects: vi.fn().mockResolvedValue([]),
}));
// ── Helpers ──────────────────────────────────────────────────────────────────
class ProcessExitError extends Error {
constructor(readonly code: number) {
super(`process.exit(${code})`);
}
}
function stubProcessExit() {
return vi.spyOn(process, 'exit').mockImplementation(((code?: number) => {
throw new ProcessExitError(code ?? 0);
}) as never);
}
const originalCwd = process.cwd();
let projectDir: string;
let errorSpy: ReturnType<typeof vi.spyOn>;
let logSpy: ReturnType<typeof vi.spyOn>;
let exitStub: ReturnType<typeof stubProcessExit>;
function buildTestProgram(): Command {
const program = new Command('mosaic').exitOverride();
registerPrdyCommand(program);
return program;
}
function runPrdy(args: string[]): Promise<unknown> {
return buildTestProgram().parseAsync(['prdy', ...args], { from: 'user' });
}
function importableDocument(overrides: Record<string, unknown> = {}): Record<string, unknown> {
return {
id: 'cmd-import-prd',
title: 'Command Import PRD',
status: 'approved', // must be forced to draft: validity is not approval
projectPath: '/tmp/elsewhere',
template: 'software',
version: 1,
sections: [
{ id: 'introduction', title: 'Introduction', fields: { context: 'x', objective: 'y' } },
],
missions: [],
createdAt: '2026-01-01T00:00:00.000Z',
updatedAt: '2026-01-01T00:00:00.000Z',
...overrides,
};
}
beforeEach(async () => {
projectDir = await mkdtemp(path.join(os.tmpdir(), 'mosaic-prdy-'));
process.chdir(projectDir);
exitStub = stubProcessExit();
errorSpy = vi.spyOn(console, 'error').mockImplementation(() => {});
logSpy = vi.spyOn(console, 'log').mockImplementation(() => {});
});
afterEach(() => {
// Restore only the per-test spies: module factory mocks must keep their
// implementations for the next test.
exitStub.mockRestore();
errorSpy.mockRestore();
logSpy.mockRestore();
process.chdir(originalCwd);
});
// ── Tests ────────────────────────────────────────────────────────────────────
describe('mosaic prdy (thin adapter over PrdService)', () => {
it('non-interactive --init creates a PRD in the docs/prdy authority store', async () => {
await runPrdy(['--init', 'Adapter Created']);
const files = await readdir(path.join(projectDir, 'docs', 'prdy'));
expect(files).toHaveLength(1);
expect(files[0]).toMatch(/\.yaml$/);
const docs = await new PrdService({ projectPath: projectDir }).list();
expect(docs).toHaveLength(1);
expect(docs[0]?.title).toBe('Adapter Created');
expect(docs[0]?.version).toBe(1);
expect(logSpy).toHaveBeenCalledWith(expect.stringContaining('PRD created'));
});
it('--import <file> creates a valid import through the service', async () => {
const filePath = path.join(projectDir, 'incoming.yaml');
await writeFile(filePath, stringifyYaml(importableDocument()), 'utf8');
await runPrdy(['--import', filePath]);
const docs = await new PrdService({ projectPath: projectDir }).list();
expect(docs).toHaveLength(1);
expect(docs[0]?.id).toBe('cmd-import-prd');
expect(docs[0]?.status).toBe('draft'); // import ≠ approval
expect(logSpy).toHaveBeenCalledWith(expect.stringContaining('Imported PRD cmd-import-prd'));
});
it('--import of a structurally-invalid file is a typed refusal that creates nothing', async () => {
const filePath = path.join(projectDir, 'broken.yaml');
await writeFile(filePath, stringifyYaml({ id: 'incomplete', no: 'structure' }), 'utf8');
await expect(runPrdy(['--import', filePath])).rejects.toBeInstanceOf(ProcessExitError);
// Typed refusal surfaced to the user, nothing created.
expect(errorSpy).toHaveBeenCalledWith(expect.stringContaining('PRD wizard failed'));
await expect(readdir(path.join(projectDir, 'docs'))).rejects.toMatchObject({ code: 'ENOENT' });
});
it('--import on conflict refuses with a successor proposal and leaves bytes untouched', async () => {
const service = new PrdService({ projectPath: projectDir });
const existing = await service.create({ name: 'Conflict Target' });
const storeFile = path.join(projectDir, 'docs', 'prdy', `${existing.id}.yaml`);
const beforeBytes = await readFile(storeFile, 'utf8');
const filePath = path.join(projectDir, 'divergent.yaml');
await writeFile(
filePath,
stringifyYaml(
importableDocument({
...existing,
title: 'Divergent Command Import',
}),
),
'utf8',
);
await expect(runPrdy(['--import', filePath])).rejects.toBeInstanceOf(ProcessExitError);
expect(errorSpy).toHaveBeenCalledWith(expect.stringContaining('refusing to overwrite'));
expect(errorSpy).toHaveBeenCalledWith(expect.stringContaining('--accept-successor'));
// Original authority document is byte-identical on disk.
expect(await readFile(storeFile, 'utf8')).toBe(beforeBytes);
});
it('--import --accept-successor persists the successor version explicitly', async () => {
const service = new PrdService({ projectPath: projectDir });
const existing = await service.create({ name: 'Successor Target' });
const filePath = path.join(projectDir, 'divergent2.yaml');
await writeFile(
filePath,
stringifyYaml(
importableDocument({
...existing,
title: 'Accepted Via CLI',
}),
),
'utf8',
);
await runPrdy(['--import', filePath, '--accept-successor']);
const doc = await service.get(existing.id);
expect(doc.version).toBe(2);
expect(doc.title).toBe('Accepted Via CLI');
expect(doc.status).toBe('draft');
expect(logSpy).toHaveBeenCalledWith(expect.stringContaining('successor'));
});
it('--export writes a labeled generated view and never touches authority', async () => {
const service = new PrdService({ projectPath: projectDir });
const created = await service.create({ name: 'Export Via CLI' });
const before = await service.get(created.id);
await runPrdy(['--export', created.id]);
const mdPath = path.join(projectDir, 'docs', 'prdy', `${created.id}.md`);
const md = await readFile(mdPath, 'utf8');
expect(md).toContain('generated view — do not edit');
expect(md).toContain(`prd-id: ${created.id}`);
expect(md).toContain('prd-version: 1');
expect(logSpy).toHaveBeenCalledWith(
expect.stringContaining(`Generated view written: ${mdPath}`),
);
// Authority unchanged by the export.
expect(await service.get(created.id)).toEqual(before);
});
});
+6 -65
View File
@@ -2,10 +2,6 @@ import type { Command } from 'commander';
import { withAuth } from './with-auth.js';
import { fetchProjects } from '../tui/gateway-api.js';
/**
* `mosaic prdy` thin adapter over PrdService (@mosaicstack/prdy).
* All reads/writes go through the service; there is no local writer path.
*/
export function registerPrdyCommand(program: Command) {
const cmd = program
.command('prdy')
@@ -13,18 +9,12 @@ export function registerPrdyCommand(program: Command) {
.option('-g, --gateway <url>', 'Gateway URL', 'http://localhost:14242')
.option('--init [name]', 'Create a new PRD')
.option('--update [name]', 'Update an existing PRD')
.option('--import <file>', 'Import a YAML PRD document (validated, conflict-aware)')
.option('--accept-successor', 'With --import: accept a conflicted import as next version')
.option('--export [id]', 'Export a PRD as a labeled generated-view Markdown file')
.option('--project <idOrName>', 'Scope to project')
.action(
async (opts: {
gateway: string;
init?: string | boolean;
update?: string | boolean;
import?: string;
acceptSuccessor?: boolean;
export?: string | boolean;
project?: string;
}) => {
// Detect project context when --project flag is provided
@@ -41,69 +31,20 @@ export function registerPrdyCommand(program: Command) {
}
}
const { PrdService, runPrdWizard } = await import('@mosaicstack/prdy');
const service = new PrdService({ projectPath: process.cwd() });
try {
if (opts.import !== undefined) {
const input = { filePath: opts.import };
if (opts.acceptSuccessor) {
const successor = await service.acceptSuccessor(input);
console.log(
`Import accepted as successor: ${successor.id} v${successor.version} (status: ${successor.status})`,
);
return;
}
const result = await service.importDocument(input);
console.log(
result.kind === 'created'
? `Imported PRD ${result.document.id} v${result.document.version} (status: ${result.document.status})`
: `PRD ${result.document.id} already present with identical content — nothing to do.`,
);
return;
}
if (opts.export !== undefined) {
const id =
typeof opts.export === 'string' && opts.export.length > 0 ? opts.export : undefined;
const result = await service.exportMarkdown({ id });
console.log(
`Generated view written: ${result.filePath} (source authority: YAML under docs/prdy/ — do not edit the Markdown)`,
);
return;
}
const { runPrdWizard } = await import('@mosaicstack/prdy');
const name =
typeof opts.init === 'string'
? opts.init
: typeof opts.update === 'string'
? opts.update
: 'untitled';
if (process.stdout.isTTY) {
await runPrdWizard({
name,
projectPath: process.cwd(),
interactive: true,
});
return;
}
// Non-interactive fallback routes through the service directly.
const doc = await service.create({ name });
console.log(`PRD created: ${doc.id} v${doc.version} (status: ${doc.status})`);
await runPrdWizard({
name,
projectPath: process.cwd(),
interactive: true,
});
} catch (err) {
if (err instanceof Error && err.name === 'PrdImportConflictError') {
const conflict = err as { proposal?: { version?: number } };
console.error(`${err.message}`);
console.error(
`Original PRD left untouched. To accept the proposed successor (v${conflict.proposal?.version}), re-run with --accept-successor.`,
);
process.exit(1);
}
console.error(`PRD wizard failed: ${err instanceof Error ? err.message : String(err)}`);
process.exit(1);
}
@@ -459,6 +459,7 @@ describe('FCM-M3-002 reconciler lifecycle acceptance', (): void => {
plan: {
generation: 7,
holder: 'owned',
broker: { unitInstalled: false, socketPresent: false },
agents: [
{
name: 'coder0',
@@ -92,6 +92,112 @@ async function run(command: FleetReconcileCommand, overrides: Partial<FleetRecon
}
describe('fleet roster-owned reconciler', (): void => {
// ── #1292: broker as first-class plan member + broker-first start ordering ──
it('reports broker unit and socket state in the plan (socket is the signal, not unit state)', async (): Promise<void> => {
const result = await run('status', {
statPath: async () => true,
checkBrokerSocket: async () => true,
});
expect(result.plan.broker).toEqual({ unitInstalled: true, socketPresent: true });
});
it('reports a dead broker as socketPresent=false even when the unit is installed (enabled-but-dead is the #1292 shape)', async (): Promise<void> => {
const result = await run('status', {
statPath: async () => true,
checkBrokerSocket: async () => false,
});
expect(result.plan.broker).toEqual({ unitInstalled: true, socketPresent: false });
});
it('reports broker-absent when neither seam is present (defaults false, never guesses healthy)', async (): Promise<void> => {
const result = await run('status');
expect(result.plan.broker).toEqual({ unitInstalled: false, socketPresent: false });
});
it('command start enables and starts the broker BEFORE the holder and any agent unit', async (): Promise<void> => {
const calls: string[][] = [];
const result = await run('start', {
runner: async (command, args) => {
calls.push([command, ...args]);
if (command === 'tmux' && args.includes('list-sessions')) {
return { stdout: '_holder\ncoder0\n', stderr: '', exitCode: 0 };
}
if (command === 'tmux' && args.includes('show-environment')) {
return {
stdout:
'HOME=/home/mosaic\nMOSAIC_FLEET_OWNER=11111111-1111-4111-8111-111111111111\nMOSAIC_TMUX_HOLDER=_holder\nMOSAIC_TMUX_SOCKET=mosaic-fleet\nPATH=/usr/bin:/bin\nPWD=/home/mosaic\n',
stderr: '',
exitCode: 0,
};
}
return { stdout: '', stderr: '', exitCode: 0 };
},
});
expect(result.lifecycle).toBe('complete');
const brokerEnable = calls.findIndex(
(c) => c.join(' ') === 'systemctl --user enable mosaic-lease-broker.service',
);
const brokerStart = calls.findIndex(
(c) => c.join(' ') === 'systemctl --user start mosaic-lease-broker.service',
);
const holderStart = calls.findIndex(
(c) => c.join(' ') === 'systemctl --user start mosaic-tmux-holder.service',
);
const agentStart = calls.findIndex(
(c) => c.join(' ') === 'systemctl --user start [email protected]',
);
expect(brokerEnable).toBeGreaterThanOrEqual(0);
expect(brokerStart).toBeGreaterThan(brokerEnable);
// Holder start may be absent (holder 'owned' in this fixture); if present it must follow the broker.
if (holderStart >= 0) expect(holderStart).toBeGreaterThan(brokerStart);
expect(agentStart).toBeGreaterThan(brokerStart);
});
it('apply with a running desired agent also enables and starts the broker first', async (): Promise<void> => {
const calls: string[][] = [];
const runningRoster: FleetRosterV2 = {
...roster,
agents: roster.agents.map((agent) =>
agent.name === 'coder0'
? { ...agent, lifecycle: { enabled: true, desiredState: 'running' as const } }
: agent,
),
};
const result = await executeFleetReconcile({
roster: runningRoster,
command: 'apply',
expectedGeneration: 7,
deps: deps({
readRoster: async () => runningRoster,
runner: async (command, args) => {
calls.push([command, ...args]);
if (command === 'tmux' && args.includes('list-sessions')) {
return { stdout: '_holder\n', stderr: '', exitCode: 0 };
}
if (command === 'tmux' && args.includes('show-environment')) {
return {
stdout:
'HOME=/home/mosaic\nMOSAIC_FLEET_OWNER=11111111-1111-4111-8111-111111111111\nMOSAIC_TMUX_HOLDER=_holder\nMOSAIC_TMUX_SOCKET=mosaic-fleet\nPATH=/usr/bin:/bin\nPWD=/home/mosaic\n',
stderr: '',
exitCode: 0,
};
}
return { stdout: '', stderr: '', exitCode: 0 };
},
}),
});
expect(result.applied).toBe(true);
const brokerStart = calls.findIndex(
(c) => c.join(' ') === 'systemctl --user start mosaic-lease-broker.service',
);
const agentStart = calls.findIndex(
(c) => c.join(' ') === 'systemctl --user start [email protected]',
);
expect(brokerStart).toBeGreaterThanOrEqual(0);
expect(agentStart).toBeGreaterThan(brokerStart);
});
it('fails closed on a symlinked fleet ancestor without touching its target', async (): Promise<void> => {
const home = await lockHome();
const fleet = join(home, 'fleet');
@@ -43,6 +43,10 @@ export interface FleetReconcileDeps {
readonly overrideDir?: string;
readonly homeDirectory?: string;
readonly readHolderIdentity?: () => Promise<string>;
/** Test/observation seams for the lease-broker plan member (#1292). */
readonly statPath?: (path: string) => Promise<boolean> | boolean;
readonly checkBrokerSocket?: (path: string) => Promise<boolean> | boolean;
readonly brokerSocketEnv?: NodeJS.ProcessEnv;
readonly validateRoster?: (roster: FleetRosterV2) => Promise<void>;
readonly prepareProjections?: (roster: FleetRosterV2) => Promise<readonly unknown[]>;
readonly applyProjection?: (prepared: unknown) => Promise<unknown>;
@@ -74,6 +78,17 @@ export interface FleetReconcileObservedAgent {
export interface FleetReconcilePlan {
readonly generation: number;
readonly holder: 'owned' | 'missing' | 'ownership-mismatch';
/**
* Lease broker observation (#1292): every gated runtime registers with the
* broker or dies ~4s in a broker not in the plan cannot be reported as
* drifted, which made "broker died an hour ago" and "broker fine"
* produce identical output. `unitInstalled` = unit file present in the
* active dir; `socketPresent` = live broker at the resolved socket path.
*/
readonly broker: {
readonly unitInstalled: boolean;
readonly socketPresent: boolean;
};
readonly agents: readonly FleetReconcileObservedAgent[];
readonly unmanagedSessions: readonly string[];
}
@@ -314,6 +329,39 @@ function isObservational(command: FleetReconcileCommand): boolean {
return command === 'plan' || command === 'status' || command === 'verify' || command === 'doctor';
}
/**
* Observe the lease broker for the plan (#1292). Unit presence via systemctl
* is-system-running is NOT the signal a unit can be enabled-but-dead. The
* authoritative signal is the socket the gated runtimes connect to, matching
* broker-supervisor.ts's `checkBrokerSupervisorHealth` (healthy ===
* socketPresent). Injectable so tests drive every branch without a broker.
*/
async function observeBroker(deps: FleetReconcileDeps): Promise<FleetReconcilePlan['broker']> {
const homeDirectory = deps.homeDirectory ?? homedir();
const env = (deps.brokerSocketEnv ?? process.env) as NodeJS.ProcessEnv;
const uid = typeof process.getuid === 'function' ? process.getuid() : 0;
const runtimeDir = env['XDG_RUNTIME_DIR'] ?? `/run/user/${uid}`;
const socketPath =
env['MOSAIC_LEASE_BROKER_SOCKET'] ?? join(runtimeDir, 'mosaic-lease', 'broker.sock');
const configHome = env['XDG_CONFIG_HOME'] ?? join(homeDirectory, '.config');
const unitPath = join(configHome, 'systemd', 'user', 'mosaic-lease-broker.service');
const statPath = deps.statPath;
const checkBrokerSocket = deps.checkBrokerSocket;
let unitInstalled = false;
let socketPresent = false;
try {
unitInstalled = statPath ? await statPath(unitPath) : false;
} catch {
unitInstalled = false;
}
try {
socketPresent = checkBrokerSocket ? await checkBrokerSocket(socketPath) : false;
} catch {
socketPresent = false;
}
return { unitInstalled, socketPresent };
}
async function observeFleet(
roster: FleetRosterV2,
deps: FleetReconcileDeps,
@@ -324,10 +372,12 @@ async function observeFleet(
'-F',
'#{session_name}',
]);
const broker = await observeBroker(deps);
if (sessionsResult.exitCode !== 0) {
return {
generation: roster.generation,
holder: 'missing',
broker,
agents: await observeAgents(roster, deps, new Set<string>()),
unmanagedSessions: [],
};
@@ -350,6 +400,7 @@ async function observeFleet(
return {
generation: roster.generation,
holder,
broker,
agents: await observeAgents(roster, deps, sessions),
unmanagedSessions: Object.freeze(unmanagedSessions.sort()),
};
@@ -517,6 +568,24 @@ async function executeExplicitLifecycle(
}
}
try {
// Broker FIRST (#1292): a gated runtime started without a running lease
// broker dies ~4 seconds in at registration — enable the unit (install
// places it) and start it before any holder/agent lifecycle effect. The
// socket re-check after start is the same probe observeBroker uses, so a
// unit that starts but never produces a socket is caught here, not four
// seconds later inside a doomed seat.
if (request.command === 'start') {
await runChecked(request.deps, 'systemctl', [
'--user',
'enable',
'mosaic-lease-broker.service',
]);
await runChecked(request.deps, 'systemctl', [
'--user',
'start',
'mosaic-lease-broker.service',
]);
}
if (request.command === 'start' && plan.holder === 'missing') {
await runChecked(request.deps, 'systemctl', [
'--user',
@@ -562,6 +631,12 @@ async function applyDesiredLifecycle(
(agent: FleetRosterV2Agent): boolean =>
agent.lifecycle.enabled && agent.lifecycle.desiredState === 'running',
);
// Broker before any running agent, same ordering and reason as the
// command-driven path above (#1292).
if (needsRunningAgent) {
await runChecked(deps, 'systemctl', ['--user', 'enable', 'mosaic-lease-broker.service']);
await runChecked(deps, 'systemctl', ['--user', 'start', 'mosaic-lease-broker.service']);
}
if (needsRunningAgent && plan.holder === 'missing') {
await runChecked(deps, 'systemctl', ['--user', 'start', 'mosaic-tmux-holder.service']);
}
+14 -74
View File
@@ -1,6 +1,6 @@
import { Command } from 'commander';
import { PrdService } from './service.js';
import { createPrd, listPrds, loadPrd } from './prd.js';
import { runPrdWizard } from './wizard.js';
interface InitCommandOptions {
@@ -18,22 +18,6 @@ interface ShowCommandOptions {
readonly id?: string;
}
interface ImportCommandOptions {
readonly project: string;
readonly file: string;
readonly acceptSuccessor?: boolean;
}
interface ExportCommandOptions {
readonly project: string;
readonly id?: string;
readonly out?: string;
}
function serviceFor(project: string): PrdService {
return new PrdService({ projectPath: project });
}
export function buildPrdyCli(): Command {
const program = new Command();
program.name('mosaic').description('Mosaic CLI').exitOverride();
@@ -54,9 +38,11 @@ export function buildPrdyCli(): Command {
template: options.template,
interactive: true,
})
: await serviceFor(options.project).create({
: await createPrd({
name: options.name,
projectPath: options.project,
template: options.template,
interactive: false,
});
console.log(
@@ -66,7 +52,6 @@ export function buildPrdyCli(): Command {
id: doc.id,
title: doc.title,
status: doc.status,
version: doc.version,
projectPath: doc.projectPath,
},
null,
@@ -80,7 +65,7 @@ export function buildPrdyCli(): Command {
.description('List PRD documents for a project')
.requiredOption('--project <path>', 'Project path')
.action(async (options: ListCommandOptions) => {
const docs = await serviceFor(options.project).list();
const docs = await listPrds(options.project);
console.log(JSON.stringify(docs, null, 2));
});
@@ -90,65 +75,20 @@ export function buildPrdyCli(): Command {
.requiredOption('--project <path>', 'Project path')
.option('--id <id>', 'PRD document id')
.action(async (options: ShowCommandOptions) => {
const doc = await serviceFor(options.project).get(options.id);
console.log(JSON.stringify(doc, null, 2));
});
if (options.id !== undefined) {
const docs = await listPrds(options.project);
const match = docs.find((doc) => doc.id === options.id);
prdy
.command('import')
.description('Import a YAML PRD document (validated; conflicts propose a successor)')
.requiredOption('--project <path>', 'Project path')
.requiredOption('--file <file>', 'Path to YAML PRD document')
.option('--accept-successor', 'Accept a conflicted import as the next version')
.action(async (options: ImportCommandOptions) => {
const service = serviceFor(options.project);
const input = { filePath: options.file };
if (match === undefined) {
throw new Error(`PRD id not found: ${options.id}`);
}
if (options.acceptSuccessor) {
const successor = await service.acceptSuccessor(input);
console.log(
JSON.stringify(
{
ok: true,
outcome: 'successor-accepted',
id: successor.id,
version: successor.version,
},
null,
2,
),
);
console.log(JSON.stringify(match, null, 2));
return;
}
const result = await service.importDocument(input);
console.log(
JSON.stringify(
{
ok: true,
outcome: result.kind,
id: result.document.id,
version: result.document.version,
status: result.document.status,
},
null,
2,
),
);
});
prdy
.command('export')
.description('Render a PRD to a labeled generated-view Markdown file')
.requiredOption('--project <path>', 'Project path')
.option('--id <id>', 'PRD document id')
.option('--out <path>', 'Output path (default docs/prdy/<id>.md)')
.action(async (options: ExportCommandOptions) => {
const result = await serviceFor(options.project).exportMarkdown({
id: options.id,
outPath: options.out,
});
console.log(JSON.stringify({ ok: true, filePath: result.filePath }, null, 2));
const doc = await loadPrd(options.project);
console.log(JSON.stringify(doc, null, 2));
});
return program;
+1 -24
View File
@@ -1,35 +1,12 @@
// PrdService is the single authority surface for PRD documents. The raw store
// writers (createPrd/savePrd) are deliberately NOT exported: every mutation
// goes through the service so there is no second writer path.
export { loadPrd, listPrds, parsePrdDocument } from './prd.js';
export { createPrd, loadPrd, savePrd, listPrds } from './prd.js';
export { runPrdWizard } from './wizard.js';
export { buildPrdyCli, runPrdyCli } from './cli.js';
export { BUILTIN_PRD_TEMPLATES, resolveTemplate } from './templates.js';
export {
PrdService,
PRD_GENERATED_VIEW_LABEL,
PrdError,
PrdNotFoundError,
PrdUpdateError,
PrdImportInvalidError,
PrdImportConflictError,
} from './service.js';
export type {
PrdStatus,
PrdTemplate,
PrdTemplateSection,
PrdSection,
PrdMissionLinkage,
PrdDocument,
CreatePrdOptions,
PrdServiceOptions,
PrdCreateInput,
PrdSectionPatch,
PrdUpdateInput,
PrdLinkMissionInput,
PrdPlanForMissionInput,
PrdExportInput,
PrdExportResult,
PrdImportInput,
PrdImportResult,
} from './types.js';
+1 -37
View File
@@ -17,49 +17,17 @@ const prdSectionSchema = z.object({
fields: z.record(z.string(), z.string()),
});
const prdMissionLinkageSchema = z.object({
missionId: z.string().min(1),
missionVersion: z.string().min(1),
prdVersion: z.number().int().min(1),
requirementIds: z.array(z.string()),
linkedAt: z.string().datetime(),
});
const prdDocumentSchema = z.object({
id: z.string().min(1),
title: z.string().min(1),
status: z.enum(['draft', 'review', 'approved', 'archived']),
projectPath: z.string().min(1),
template: z.string().min(1),
// Defaults keep documents written by older prdy versions loadable.
version: z.number().int().min(1).default(1),
sections: z.array(prdSectionSchema),
missions: z.array(prdMissionLinkageSchema).default([]),
createdAt: z.string().datetime(),
updatedAt: z.string().datetime(),
});
/** YAML timestamp scalars are parsed as Date by some emitters — normalize to ISO strings. */
function coerceTimestamps(value: unknown): unknown {
if (value instanceof Date) {
return value.toISOString();
}
if (Array.isArray(value)) {
return value.map(coerceTimestamps);
}
if (typeof value === 'object' && value !== null) {
return Object.fromEntries(
Object.entries(value).map(([key, entry]) => [key, coerceTimestamps(entry)]),
);
}
return value;
}
/** Validate an unknown value as a PRD document (throws zod errors on failure). */
export function parsePrdDocument(value: unknown): PrdDocument {
return prdDocumentSchema.parse(coerceTimestamps(value)) as PrdDocument;
}
function expandHome(projectPath: string): string {
if (!projectPath.startsWith('~')) {
return projectPath;
@@ -106,8 +74,6 @@ function prdDirectory(projectPath: string): string {
return path.join(projectPath, PRD_DIRECTORY);
}
export { prdDirectory };
function prdFilePath(projectPath: string, id: string): string {
return path.join(prdDirectory(projectPath), `${id}.yaml`);
}
@@ -147,13 +113,11 @@ export async function createPrd(options: CreatePrdOptions): Promise<PrdDocument>
status: 'draft',
projectPath: resolvedProjectPath,
template: template.id,
version: 1,
sections: template.sections.map((section) => ({
id: section.id,
title: section.title,
fields: Object.fromEntries(section.fields.map((field) => [field, ''])),
})),
missions: [],
createdAt: now,
updatedAt: now,
};
@@ -226,7 +190,7 @@ export async function listPrds(projectPath: string): Promise<PrdDocument[]> {
throw new Error(`Failed to parse PRD file ${filePath}: ${String(error)}`);
}
const document = parsePrdDocument(parsed);
const document = prdDocumentSchema.parse(parsed);
documents.push(document);
}
-433
View File
@@ -1,433 +0,0 @@
import { existsSync } from 'node:fs';
import { mkdtemp, readFile, readdir, writeFile } from 'node:fs/promises';
import os from 'node:os';
import path from 'node:path';
import yaml from 'js-yaml';
import { beforeEach, describe, expect, it } from 'vitest';
import {
PRD_GENERATED_VIEW_LABEL,
PrdImportConflictError,
PrdImportInvalidError,
PrdNotFoundError,
PrdService,
PrdUpdateError,
} from './index.js';
import type { PrdDocument } from './index.js';
// ── Helpers ──────────────────────────────────────────────────────────────────
let projectDir: string;
async function makeProject(): Promise<string> {
return mkdtemp(path.join(os.tmpdir(), 'prdy-service-'));
}
function service(): PrdService {
return new PrdService({ projectPath: projectDir });
}
function storeDir(): string {
return path.join(projectDir, 'docs', 'prdy');
}
/** Handcraft a full, schema-valid PRD document for import scenarios. */
function importFixture(overrides: Partial<PrdDocument> = {}): PrdDocument {
return {
id: 'imported-prd-20260101-000000',
title: 'Imported PRD',
status: 'draft',
projectPath: '/tmp/elsewhere',
template: 'software',
version: 1,
sections: [
{ id: 'introduction', title: 'Introduction', fields: { context: '', objective: '' } },
{
id: 'scope-non-goals',
title: 'Scope / Non-Goals',
fields: { inScope: '', outOfScope: '' },
},
],
missions: [],
createdAt: '2026-01-01T00:00:00.000Z',
updatedAt: '2026-01-01T00:00:00.000Z',
...overrides,
};
}
async function writeImportFile(doc: PrdDocument): Promise<string> {
const filePath = path.join(projectDir, `${doc.id}.import.yaml`);
await writeFile(filePath, yaml.dump(doc), 'utf8');
return filePath;
}
beforeEach(async () => {
projectDir = await makeProject();
});
// ── Single authority store (AC: prdy path and mission path resolve to the
// SAME store under docs/prdy/ with stable ids/versions) ────────────────────
describe('PrdService single authority store', () => {
it('persists PRDs from the prdy path and the mission path into the same docs/prdy store', async () => {
const direct = await service().create({ name: 'Direct PRD' });
const viaMission = await service().planForMission({
name: 'Mission PRD',
missionId: 'mission-1',
missionVersion: '2026-01-01T00:00:00.000Z',
});
const files = await readdir(storeDir());
expect(files).toContain(`${direct.id}.yaml`);
expect(files).toContain(`${viaMission.id}.yaml`);
// A fresh service instance (new process equivalent) resolves both.
const all = await service().list();
expect(all.map((doc) => doc.id).sort()).toEqual([direct.id, viaMission.id].sort());
// Stable versions: creation is v1; linkage writes do not bump content version.
expect((await service().get(direct.id)).version).toBe(1);
expect((await service().get(viaMission.id)).version).toBe(1);
});
it('round-trips documents through the store with identity intact', async () => {
const created = await service().create({ name: 'Round Trip', template: 'feature' });
const fresh = await service().get(created.id);
expect(fresh).toEqual(created);
expect(fresh.id).toBe(created.id);
expect(fresh.template).toBe('feature');
expect(fresh.status).toBe('draft');
});
it('throws a typed error for unknown ids and empty stores', async () => {
await expect(service().get('nope')).rejects.toBeInstanceOf(PrdNotFoundError);
await expect(service().get()).rejects.toBeInstanceOf(PrdNotFoundError);
});
});
// ── Mission linkage persistence (AC: linkage survives restart via fresh
// service instances) ────────────────────────────────────────────────────────
describe('PrdService mission linkage', () => {
it('persists linkage and reads it back from a fresh service instance', async () => {
const created = await service().planForMission({
name: 'Linked PRD',
missionId: 'mission-42',
missionVersion: '2026-02-03T04:05:06.000Z',
requirementIds: ['FR-1', 'FR-2'],
});
// Fresh instance — nothing in memory from the creating call.
const links = await service().listMissionLinks(created.id);
expect(links).toHaveLength(1);
expect(links[0]).toMatchObject({
missionId: 'mission-42',
missionVersion: '2026-02-03T04:05:06.000Z',
prdVersion: 1,
requirementIds: ['FR-1', 'FR-2'],
});
// Linkage is carried in the YAML authority file itself.
const raw = await readFile(path.join(storeDir(), `${created.id}.yaml`), 'utf8');
const persisted = yaml.load(raw) as PrdDocument;
expect(persisted.missions[0]?.missionId).toBe('mission-42');
expect(persisted.missions[0]?.requirementIds).toEqual(['FR-1', 'FR-2']);
});
it('refreshes an existing linkage entry in place instead of duplicating', async () => {
const created = await service().planForMission({
name: 'Relink PRD',
missionId: 'mission-7',
missionVersion: 'v1',
});
await service().update({
id: created.id,
sections: [{ id: 'introduction', fields: { objective: 'Ship it' } }],
});
const relinked = await service().linkMission({
prdId: created.id,
missionId: 'mission-7',
missionVersion: 'v2',
requirementIds: ['NFR-1'],
});
expect(relinked.missions).toHaveLength(1);
expect(relinked.missions[0]).toMatchObject({ missionVersion: 'v2', prdVersion: 2 });
});
it('does not bump the content version when writing linkage', async () => {
const created = await service().create({ name: 'Stable Version' });
const linked = await service().linkMission({
prdId: created.id,
missionId: 'm',
missionVersion: 'v1',
});
expect(linked.version).toBe(1);
});
});
// ── Update semantics ──────────────────────────────────────────────────────────
describe('PrdService update', () => {
it('applies section patches and bumps the content version', async () => {
const created = await service().create({ name: 'Updatable' });
const updated = await service().update({
id: created.id,
sections: [{ id: 'introduction', fields: { context: 'Some context', objective: 'Goal' } }],
});
expect(updated.version).toBe(2);
expect(updated.sections[0]?.fields).toMatchObject({
context: 'Some context',
objective: 'Goal',
});
expect((await service().get(created.id)).version).toBe(2);
});
it('refuses unknown section ids with a typed error', async () => {
const created = await service().create({ name: 'Strict' });
await expect(
service().update({ id: created.id, sections: [{ id: 'nope', fields: {} }] }),
).rejects.toBeInstanceOf(PrdUpdateError);
});
});
// ── Markdown export is a labeled generated view, never authority ──────────────
describe('PrdService exportMarkdown', () => {
it('writes a generated view carrying the label and source identity', async () => {
const created = await service().create({ name: 'Exported PRD' });
const result = await service().exportMarkdown({ id: created.id });
expect(result.filePath).toBe(path.join(storeDir(), `${created.id}.md`));
expect(result.content).toContain(PRD_GENERATED_VIEW_LABEL);
expect(result.content).toContain(`prd-id: ${created.id}`);
expect(result.content).toContain('prd-version: 1');
expect(result.content).toContain(`source-of-truth: docs/prdy/${created.id}.yaml`);
});
it('reflects the current version after updates', async () => {
const created = await service().create({ name: 'Versioned Export' });
await service().update({
id: created.id,
sections: [{ id: 'introduction', fields: { objective: 'v2 goal' } }],
});
const result = await service().exportMarkdown({ id: created.id });
expect(result.content).toContain('prd-version: 2');
});
it('NEGATIVE CONTROL: mutating the exported Markdown cannot change the authority', async () => {
const created = await service().create({ name: 'Guarded PRD' });
const before = structuredClone(await service().get(created.id));
const result = await service().exportMarkdown({ id: created.id });
await writeFile(
result.filePath,
`<!-- ${PRD_GENERATED_VIEW_LABEL} -->\n# FAKE\nprd-id: fake-id\nprd-version: 99\n`,
'utf8',
);
const after = await service().get(created.id);
expect(after).toEqual(before);
expect(after.version).toBe(1);
expect(after.title).toBe(before.title);
});
it('never parses Markdown files that sit in the store directory', async () => {
const created = await service().create({ name: 'Decoy Guard' });
// A decoy .md file with invalid YAML must be invisible to the store.
await writeFile(path.join(storeDir(), 'decoy.md'), 'not: [valid: yaml', 'utf8');
// And a decoy .yaml-named Markdown body must not silently validate either.
await service().exportMarkdown({ id: created.id });
const listed = await service().list();
expect(listed.map((doc) => doc.id)).toEqual([created.id]);
await expect(service().get(created.id)).resolves.toBeTruthy();
});
});
// ── Import: validated, conflict-aware, never silently merging ─────────────────
describe('PrdService importDocument', () => {
it('creates a valid import through the service, as draft — validity is not approval', async () => {
const filePath = await writeImportFile(importFixture({ status: 'approved' }));
const result = await service().importDocument({ filePath });
expect(result.kind).toBe('created');
expect(result.document.id).toBe('imported-prd-20260101-000000');
expect(result.document.status).toBe('draft'); // structural validity ≠ approval
expect(result.document.version).toBe(1);
const persisted = await service().get('imported-prd-20260101-000000');
expect(persisted.status).toBe('draft');
const files = await readdir(storeDir());
expect(files).toContain('imported-prd-20260101-000000.yaml');
});
it('reports identical content as a no-op without writing', async () => {
const created = await service().create({ name: 'Existing PRD' });
const before = await readFile(path.join(storeDir(), `${created.id}.yaml`), 'utf8');
const filePath = await writeImportFile(importFixture({ ...created }));
const result = await service().importDocument({ filePath });
expect(result.kind).toBe('identical');
const after = await readFile(path.join(storeDir(), `${created.id}.yaml`), 'utf8');
expect(after).toBe(before);
});
it('refuses a conflicting import with a typed error, a proposed successor, and untouched bytes', async () => {
const existing = await service().create({ name: 'Authority PRD' });
await service().linkMission({
prdId: existing.id,
missionId: 'mission-keep',
missionVersion: 'v1',
requirementIds: ['FR-0'],
});
const beforeBytes = await readFile(path.join(storeDir(), `${existing.id}.yaml`), 'utf8');
const divergent = importFixture({
...existing,
title: 'Divergent Title',
sections: [
{
id: 'introduction',
title: 'Introduction',
fields: { context: 'changed', objective: '' },
},
],
});
const filePath = await writeImportFile(divergent);
const attempt = service().importDocument({ filePath });
let caught: unknown;
try {
await attempt;
} catch (error) {
caught = error;
}
expect(caught).toBeInstanceOf(PrdImportConflictError);
const error = caught as PrdImportConflictError;
expect(error.code).toBe('PRD_IMPORT_CONFLICT');
expect(error.existing.id).toBe(existing.id);
expect(error.proposal.version).toBe(existing.version + 1); // successor proposal
expect(error.proposal.status).toBe('draft');
// Original authority content untouched on disk.
const afterBytes = await readFile(path.join(storeDir(), `${existing.id}.yaml`), 'utf8');
expect(afterBytes).toBe(beforeBytes);
});
it('acceptSuccessor persists the proposal explicitly, carrying linkages forward', async () => {
const existing = await service().create({ name: 'Successor Base' });
await service().linkMission({
prdId: existing.id,
missionId: 'mission-keep',
missionVersion: 'v1',
});
const divergent = importFixture({
...existing,
title: 'Accepted Successor Title',
});
const filePath = await writeImportFile(divergent);
const successor = await service().acceptSuccessor({ filePath });
expect(successor.id).toBe(existing.id);
expect(successor.version).toBe(existing.version + 1);
expect(successor.title).toBe('Accepted Successor Title');
expect(successor.status).toBe('draft');
expect(successor.missions.map((m) => m.missionId)).toEqual(['mission-keep']);
// Persisted for a fresh reader.
const fresh = await service().get(existing.id);
expect(fresh.version).toBe(2);
expect(fresh.title).toBe('Accepted Successor Title');
});
it('refuses structurally-invalid imports with a typed error and creates nothing', async () => {
const cases: Array<{ name: string; body: string }> = [
{ name: 'missing-title.yaml', body: yaml.dump({ id: 'x', status: 'draft' }) },
{
name: 'bad-status.yaml',
body: yaml.dump(importFixture({ status: 'not-a-status' as PrdDocument['status'] })),
},
{
name: 'bad-version.yaml',
body: yaml.dump(importFixture({ version: 0 })),
},
{ name: 'not-yaml.yaml', body: '::: not yaml [\n - {' },
];
for (const fixture of cases) {
const filePath = path.join(projectDir, fixture.name);
await writeFile(filePath, fixture.body, 'utf8');
await expect(service().importDocument({ filePath })).rejects.toBeInstanceOf(
PrdImportInvalidError,
);
}
// Nothing was created: the authority store does not even exist yet.
await expect(readdir(storeDir())).rejects.toMatchObject({ code: 'ENOENT' });
});
it('acceptSuccessor refuses when there is no existing document to succeed', async () => {
const filePath = await writeImportFile(importFixture());
await expect(service().acceptSuccessor({ filePath })).rejects.toBeInstanceOf(PrdNotFoundError);
});
});
// ── No second writer: no code path reads exported Markdown back into authority ─
describe('no-second-writer invariant (source-level)', () => {
// Resolve the package source dir whether vitest runs from the package root
// (turbo/pnpm test) or from the worktree root.
function resolveSrcDir(): string {
const candidates = [path.resolve('src'), path.resolve('packages/prdy/src')];
return candidates.find((dir) => existsSync(path.join(dir, 'service.ts'))) ?? candidates[0]!;
}
const srcDir = resolveSrcDir();
const sourceFiles = [
'cli.ts',
'index.ts',
'prd.ts',
'service.ts',
'templates.ts',
'types.ts',
'wizard.ts',
];
it('no source file in @mosaicstack/prdy reads a .md file', async () => {
for (const file of sourceFiles) {
const text = await readFile(path.join(srcDir, file), 'utf8');
const readLines = text
.split('\n')
.map((line) => line.trim())
.filter((line) => /readFile|readFileSync|createReadStream/.test(line));
for (const line of readLines) {
expect(line.includes('.md'), `${file} reads a Markdown file: ${line}`).toBe(false);
}
}
});
it('the mosaic prdy/mission adapters never read a .md file', async () => {
const adapterDir = path.resolve(srcDir, '..', '..', 'mosaic', 'src', 'commands');
for (const file of ['prdy.ts', 'mission.ts']) {
const text = await readFile(path.join(adapterDir, file), 'utf8');
expect(text.includes("'.md'") || text.includes('.md`'), `${file} references a .md path`).toBe(
false,
);
}
});
});
-379
View File
@@ -1,379 +0,0 @@
import { promises as fs } from 'node:fs';
import path from 'node:path';
import yaml from 'js-yaml';
import { createPrd, listPrds, parsePrdDocument, prdDirectory, savePrd } from './prd.js';
import type {
PrdCreateInput,
PrdDocument,
PrdExportInput,
PrdExportResult,
PrdImportInput,
PrdImportResult,
PrdLinkMissionInput,
PrdMissionLinkage,
PrdPlanForMissionInput,
PrdServiceOptions,
PrdUpdateInput,
} from './types.js';
/**
* PrdService is the SINGLE authority surface for PRD documents.
*
* Every mutation path (CLI wizard, `mosaic mission --plan`, import) routes
* through this service; the YAML store under `docs/prdy/` is the authority and
* exported Markdown is a generated view that no code path reads back.
*/
// ── Typed errors ───────────────────────────────────────────────────────────────
export class PrdError extends Error {
constructor(
message: string,
readonly code: string,
) {
super(message);
this.name = 'PrdError';
}
}
export class PrdNotFoundError extends PrdError {
constructor(message: string) {
super(message, 'PRD_NOT_FOUND');
this.name = 'PrdNotFoundError';
}
}
export class PrdUpdateError extends PrdError {
constructor(message: string) {
super(message, 'PRD_UPDATE_INVALID');
this.name = 'PrdUpdateError';
}
}
/** Structural refusal: the import payload failed schema validation. Nothing is written. */
export class PrdImportInvalidError extends PrdError {
constructor(
message: string,
readonly issues?: string,
) {
super(message, 'PRD_IMPORT_INVALID');
this.name = 'PrdImportInvalidError';
}
}
/**
* Conflict refusal: an existing PRD shares the imported id but the content
* diverges. Carries a PROPOSED successor (existing version + 1) that is only
* persisted via an explicit {@link PrdService.acceptSuccessor} call import
* never overwrites and never merges.
*/
export class PrdImportConflictError extends PrdError {
constructor(
message: string,
readonly existing: PrdDocument,
readonly proposal: PrdDocument,
) {
super(message, 'PRD_IMPORT_CONFLICT');
this.name = 'PrdImportConflictError';
}
}
// ── Service ────────────────────────────────────────────────────────────────────
/** The generated-view label carried by every Markdown export. */
export const PRD_GENERATED_VIEW_LABEL = 'generated view — do not edit';
export class PrdService {
private readonly projectPath: string;
constructor(options: PrdServiceOptions) {
this.projectPath = options.projectPath;
}
/** Create a new PRD (version 1, draft) in the authority store. */
async create(input: PrdCreateInput): Promise<PrdDocument> {
return createPrd({
name: input.name,
projectPath: this.projectPath,
template: input.template,
interactive: false,
});
}
/** Read a PRD by id, or the most recently updated one. */
async get(id?: string): Promise<PrdDocument> {
const documents = await listPrds(this.projectPath);
if (id === undefined) {
const latest = documents[0];
if (latest === undefined) {
throw new PrdNotFoundError(`No PRD documents found under docs/prdy/ for this project`);
}
return latest;
}
const match = documents.find((doc) => doc.id === id);
if (match === undefined) {
throw new PrdNotFoundError(`PRD id not found: ${id}`);
}
return match;
}
/** List all PRDs in the authority store (most recently updated first). */
async list(): Promise<PrdDocument[]> {
return listPrds(this.projectPath);
}
/**
* Apply section field patches and bump the content version.
* Linkage entries are preserved; linkage writes do NOT bump the version.
*/
async update(input: PrdUpdateInput): Promise<PrdDocument> {
const doc = await this.get(input.id);
for (const patch of input.sections) {
const section = doc.sections.find((candidate) => candidate.id === patch.id);
if (section === undefined) {
throw new PrdUpdateError(`Unknown section id: ${patch.id}`);
}
for (const [field, value] of Object.entries(patch.fields)) {
if (!(field in section.fields)) {
throw new PrdUpdateError(`Unknown field "${field}" on section "${patch.id}"`);
}
section.fields[field] = value;
}
}
doc.version += 1;
doc.updatedAt = new Date().toISOString();
await savePrd(doc);
return doc;
}
/**
* Record (or refresh) a mission PRD linkage on the PRD document.
* Persisted in the YAML authority, so it survives restarts.
*/
async linkMission(input: PrdLinkMissionInput): Promise<PrdDocument> {
const doc = await this.get(input.prdId);
return this.applyLinkage(doc, input);
}
/** Read back the mission linkages recorded on a PRD. */
async listMissionLinks(prdId?: string): Promise<PrdMissionLinkage[]> {
const doc = await this.get(prdId);
return doc.missions;
}
/**
* Mission planning path: create a PRD for a mission AND persist the
* missionPRD linkage in a single authority write.
*/
async planForMission(input: PrdPlanForMissionInput): Promise<PrdDocument> {
const doc = await this.create({ name: input.name, template: input.template });
return this.applyLinkage(doc, {
prdId: doc.id,
missionId: input.missionId,
missionVersion: input.missionVersion,
requirementIds: input.requirementIds,
});
}
/**
* Render the PRD to a Markdown GENERATED VIEW.
*
* The output carries source identity (PRD id + version + generated-view
* label). It is written under `docs/prdy/<id>.md` and is NEVER read back:
* the authority store only loads `.yaml`/`.yml` files, and no code path in
* this package parses the exported Markdown.
*/
async exportMarkdown(input?: PrdExportInput): Promise<PrdExportResult> {
const doc = await this.get(input?.id);
const content = renderMarkdown(doc);
const filePath = input?.outPath ?? path.join(prdDirectory(doc.projectPath), `${doc.id}.md`);
await fs.mkdir(path.dirname(filePath), { recursive: true });
await fs.writeFile(filePath, content, 'utf8');
return { filePath, content };
}
/**
* Import a YAML PRD document.
*
* Structural validation (zod) happens BEFORE anything is proposed or
* written. A structurally-valid import is persisted as `draft` validity is
* NOT approval. If an existing PRD shares the id with divergent content, a
* typed {@link PrdImportConflictError} is thrown carrying a proposed
* successor; the original authority document is left byte-identical on disk.
*/
async importDocument(input: PrdImportInput): Promise<PrdImportResult> {
const incoming = await this.readImportFile(input.filePath);
const existing = (await listPrds(this.projectPath)).find((doc) => doc.id === incoming.id);
if (existing === undefined) {
const document = this.buildImportedDocument(incoming);
await savePrd(document);
return { kind: 'created', document };
}
if (canonicalCore(existing) === canonicalCore(incoming)) {
return { kind: 'identical', document: existing };
}
throw new PrdImportConflictError(
`PRD id "${incoming.id}" already exists with divergent content — refusing to overwrite. ` +
`Proposed successor: version ${existing.version + 1} (draft). ` +
`Accept explicitly with acceptSuccessor().`,
existing,
this.buildSuccessor(existing, incoming),
);
}
/**
* Explicitly accept a conflicted import as a successor version of the
* existing PRD. Re-validates the source file before writing; the successor
* is persisted with status `draft` (acceptance of the import is not approval
* of the PRD) and the existing mission linkages are carried forward.
*/
async acceptSuccessor(input: PrdImportInput): Promise<PrdDocument> {
const incoming = await this.readImportFile(input.filePath);
const existing = (await listPrds(this.projectPath)).find((doc) => doc.id === incoming.id);
if (existing === undefined) {
throw new PrdNotFoundError(
`No existing PRD with id "${incoming.id}" — use importDocument to create it`,
);
}
const successor = this.buildSuccessor(existing, incoming);
await savePrd(successor);
return successor;
}
// ── internals ──────────────────────────────────────────────────────────────
private async applyLinkage(doc: PrdDocument, input: PrdLinkMissionInput): Promise<PrdDocument> {
const entry: PrdMissionLinkage = {
missionId: input.missionId,
missionVersion: input.missionVersion,
prdVersion: doc.version,
requirementIds: input.requirementIds ?? [],
linkedAt: new Date().toISOString(),
};
// One entry per mission: refresh in place if the mission is already linked.
const index = doc.missions.findIndex((m) => m.missionId === entry.missionId);
if (index === -1) {
doc.missions.push(entry);
} else {
doc.missions[index] = entry;
}
// Linkage is mission-side metadata, not a content revision: bump the
// timestamp only so ids/versions stay stable for consumers.
doc.updatedAt = new Date().toISOString();
await savePrd(doc);
return doc;
}
private async readImportFile(filePath: string): Promise<PrdDocument> {
let raw: string;
try {
raw = await fs.readFile(filePath, 'utf8');
} catch (error) {
throw new PrdImportInvalidError(`Cannot read import file ${filePath}: ${String(error)}`);
}
let parsed: unknown;
try {
parsed = yaml.load(raw);
} catch (error) {
throw new PrdImportInvalidError(`Import file is not valid YAML: ${String(error)}`);
}
try {
return parsePrdDocument(parsed);
} catch (error) {
throw new PrdImportInvalidError(
`Import file failed PRD schema validation: ${filePath}`,
error instanceof Error ? error.message : String(error),
);
}
}
private buildImportedDocument(incoming: PrdDocument): PrdDocument {
const now = new Date().toISOString();
return {
...incoming,
// The import lands in THIS project's authority store.
projectPath: this.projectPath,
// A structurally-valid import is not thereby approved.
status: 'draft',
version: 1,
missions: [],
createdAt: now,
updatedAt: now,
};
}
private buildSuccessor(existing: PrdDocument, incoming: PrdDocument): PrdDocument {
return {
...incoming,
id: existing.id,
projectPath: existing.projectPath,
status: 'draft',
version: existing.version + 1,
missions: existing.missions,
createdAt: existing.createdAt,
updatedAt: new Date().toISOString(),
};
}
}
// ── Markdown rendering (generated view) ───────────────────────────────────────
function canonicalCore(doc: PrdDocument): string {
return JSON.stringify([doc.title, doc.template, doc.sections]);
}
function renderMarkdown(doc: PrdDocument): string {
const lines: string[] = [
'<!--',
`${PRD_GENERATED_VIEW_LABEL}`,
`source-of-truth: docs/prdy/${doc.id}.yaml (YAML authority)`,
`prd-id: ${doc.id}`,
`prd-version: ${doc.version}`,
`generated-at: ${new Date().toISOString()}`,
'-->',
'',
`# ${doc.title}`,
'',
`**Status:** ${doc.status} · **Version:** ${doc.version} · **Template:** ${doc.template}`,
'',
];
if (doc.missions.length > 0) {
lines.push('## Mission Linkage', '');
for (const mission of doc.missions) {
const requirements =
mission.requirementIds.length > 0 ? mission.requirementIds.join(', ') : 'none selected';
lines.push(
`- mission \`${mission.missionId}\` @ version \`${mission.missionVersion}\`` +
` (linked at PRD v${mission.prdVersion}) — requirements: ${requirements}`,
);
}
lines.push('');
}
for (const section of doc.sections) {
lines.push(`## ${section.title}`, '');
for (const [field, value] of Object.entries(section.fields)) {
lines.push(`### ${field}`, '', value.trim().length > 0 ? value : '_Not set_.', '');
}
}
lines.push('---', '', `_End of generated view for ${doc.id} v${doc.version}._`, '');
return lines.join('\n');
}
-75
View File
@@ -19,31 +19,13 @@ export interface PrdSection {
fields: Record<string, string>;
}
/**
* Mission PRD linkage recorded on the PRD document (the YAML authority).
*
* `missionVersion` is the mission-side revision marker available to the CLI
* (the gateway exposes `updatedAt` for missions there is no numeric mission
* version yet). `prdVersion` snapshots the PRD content version at link time.
*/
export interface PrdMissionLinkage {
missionId: string;
missionVersion: string;
prdVersion: number;
requirementIds: string[];
linkedAt: string;
}
export interface PrdDocument {
id: string;
title: string;
status: PrdStatus;
projectPath: string;
template: string;
/** Content revision counter. Bumped by updates and accepted imports. */
version: number;
sections: PrdSection[];
missions: PrdMissionLinkage[];
createdAt: string;
updatedAt: string;
}
@@ -54,60 +36,3 @@ export interface CreatePrdOptions {
template?: string;
interactive?: boolean;
}
// ── PrdService surface (single authority entry point) ─────────────────────────
export interface PrdServiceOptions {
projectPath: string;
}
export interface PrdCreateInput {
name: string;
template?: string;
}
export interface PrdSectionPatch {
id: string;
fields: Record<string, string>;
}
export interface PrdUpdateInput {
/** Defaults to the most recently updated PRD. */
id?: string;
sections: PrdSectionPatch[];
}
export interface PrdLinkMissionInput {
/** Defaults to the most recently updated PRD. */
prdId?: string;
missionId: string;
missionVersion: string;
requirementIds?: string[];
}
export interface PrdPlanForMissionInput extends PrdLinkMissionInput {
name: string;
template?: string;
}
export interface PrdExportInput {
/** Defaults to the most recently updated PRD. */
id?: string;
/** Override the generated-view output path. */
outPath?: string;
}
export interface PrdExportResult {
filePath: string;
content: string;
}
/** Discriminated result of a non-conflicting import. */
export type PrdImportResult =
| { kind: 'created'; document: PrdDocument }
| { kind: 'identical'; document: PrdDocument };
export interface PrdImportInput {
/** Path to a YAML-serialized PRD document (NOT the generated Markdown view). */
filePath: string;
}
+32 -43
View File
@@ -2,8 +2,8 @@ import path from 'node:path';
import { cancel, intro, isCancel, outro, select, text } from '@clack/prompts';
import { PrdService } from './service.js';
import type { CreatePrdOptions, PrdDocument, PrdSectionPatch } from './types.js';
import { createPrd, savePrd } from './prd.js';
import type { CreatePrdOptions, PrdDocument } from './types.js';
interface WizardAnswers {
goals: string;
@@ -11,41 +11,20 @@ interface WizardAnswers {
milestones: string;
}
/**
* Translate wizard answers into section patches using the same keyword
* matching the wizard always used (first section whose id contains the
* keyword, then first field whose name contains it, else first field).
*/
function buildWizardPatches(doc: PrdDocument, answers: WizardAnswers): PrdSectionPatch[] {
const bySection = new Map<string, PrdSectionPatch>();
function updateSectionField(doc: PrdDocument, sectionKeyword: string, value: string): void {
const section = doc.sections.find((candidate) => candidate.id.includes(sectionKeyword));
const add = (keyword: string, value: string): void => {
const section = doc.sections.find((candidate) => candidate.id.includes(keyword));
if (section === undefined) {
return;
}
if (section === undefined) {
return;
}
const fieldName =
Object.keys(section.fields).find((field) => field.toLowerCase().includes(keyword)) ??
Object.keys(section.fields)[0];
const fieldName =
Object.keys(section.fields).find((field) => field.toLowerCase().includes(sectionKeyword)) ??
Object.keys(section.fields)[0];
if (fieldName === undefined || section.fields[fieldName] === value) {
return;
}
const existing = bySection.get(section.id);
if (existing === undefined) {
bySection.set(section.id, { id: section.id, fields: { [fieldName]: value } });
} else {
existing.fields[fieldName] = value;
}
};
add('goal', answers.goals);
add('constraint', answers.constraints);
add('milestone', answers.milestones);
return [...bySection.values()];
if (fieldName !== undefined) {
section.fields[fieldName] = value;
}
}
async function promptText(message: string, initialValue = ''): Promise<string> {
@@ -84,10 +63,15 @@ async function promptTemplate(template?: string): Promise<string> {
return choice;
}
/**
* Interactive PRD wizard. All writes go through PrdService the wizard is a
* prompt layer, never a second writer path.
*/
function applyWizardAnswers(doc: PrdDocument, answers: WizardAnswers): PrdDocument {
updateSectionField(doc, 'goal', answers.goals);
updateSectionField(doc, 'constraint', answers.constraints);
updateSectionField(doc, 'milestone', answers.milestones);
doc.updatedAt = new Date().toISOString();
return doc;
}
export async function runPrdWizard(options: CreatePrdOptions): Promise<PrdDocument> {
intro('Mosaic PRD wizard');
@@ -98,15 +82,20 @@ export async function runPrdWizard(options: CreatePrdOptions): Promise<PrdDocume
const constraints = await promptText('Key constraints');
const milestones = await promptText('Planned milestones');
const service = new PrdService({ projectPath: options.projectPath });
const doc = await service.create({
const doc = await createPrd({
...options,
name,
template,
interactive: true,
});
const patches = buildWizardPatches(doc, { goals, constraints, milestones });
const updated =
patches.length > 0 ? await service.update({ id: doc.id, sections: patches }) : doc;
const updated = applyWizardAnswers(doc, {
goals,
constraints,
milestones,
});
await savePrd(updated);
outro(`PRD created: ${path.join(updated.projectPath, 'docs', 'prdy', `${updated.id}.yaml`)}`);
-37
View File
@@ -1,37 +0,0 @@
# Scratchpad — RI-4-001 One transitional PRD authority (RI-N3, #1275)
- Objective: single PrdService authority in `@mosaicstack/prdy`; `mosaic prdy` and
`mission --plan` become thin adapters; mission↔PRD linkage persisted on disk;
Markdown export is a labeled generated view (never read back); import is
validated/conflict-aware with typed refusals.
- Budget: ~35K tokens (card cap). Baselines: prdy build/lint rc=0, 0 tests;
mosaic build rc=0 (after root turbo build), lint rc=0, 1548 tests pass;
root build rc=0.
- Plan: (1) extend store schema (version, missions linkage) (2) PrdService +
typed errors (3) wizard/cli route through service (4) mosaic adapters
(5) contract specs both packages (6) gates (7) sabotage control (8) report
to /var/tmp/ri-050/ri-4-001-report.md.
- Decisions:
- Linkage lives ON the PRD document (`missions` array) — one authority file,
survives restart, no sidecar sync problems.
- `version` = content revision of sections/status (bumped by update/import
accept). Linkage writes bump `updatedAt` only, so ids/versions stay stable
for the card's "stable ids/versions" contract.
- Mission version marker = `mission.updatedAt` (gateway MissionInfo has no
numeric version field).
- Import reads YAML documents only — never the exported Markdown (keeps the
"no code path reads exported Markdown" invariant).
- Import of an existing id with identical core content → `identical` no-op;
divergent → typed `PrdImportConflictError` carrying proposed successor
(existing.version + 1, status draft, linkages preserved). Original bytes
untouched until explicit `acceptSuccessor`.
- `requirementIds` default `[]` at the mission command (no requirement
selection UI yet) — service accepts ids when a caller has them.
- Progress log:
- [16:35] baselines captured (prdy 0 tests; mosaic 1548 after root build; root build rc=0)
- [16:38] store schema v2 + PrdService + wizard/cli rerouted; prdy build/lint green
- [16:40] mosaic adapters done; prdy spec 20/20 (found+fixed: import project-path leak, empty-store typed error, YAML timestamp coercion)
- [16:44] mosaic specs 9/9 (fixed commander from:'user' argv, vi.mock hoisting, restoreAllMocks wiping factory mocks)
- [16:45] all gates green; 4 commits (e291bfb, 2c5d208, a23826c, 540d6f1)
- [16:46] sabotage: linkage write removed → prdy 3 fail / mosaic 2 fail, 1548/1548 pre-existing pass; restored byte-identically; re-green 20/20 + 1557/1557
- [16:47] report written to /var/tmp/ri-050/ri-4-001-report.md — card complete